What is CVE-2026-14226?
The Easy Appointments WordPress plugin through 3.12.26 has a vulnerability where one of its appointment-listing REST endpoints does not require sufficient capability, restricting it only to a capability that every authenticated user holds. This allows users with subscriber-level access to read all bookings on the site.
Azərbaycanca: CVE-2026-14226, Easy Appointments WordPress plaginində (3.12.26-ya qədər) autentifikasiya olunmuş istənilən istifadəçiyə (məsələn, Subscriber roluna) bütün görüş qeydlərini oxumağa imkan verən zəiflikdir. Problem REST endpoint-də kifayət qədər icazə yoxlamasının olmaması ilə bağlıdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin and versions are affected by CVE-2026-14226?
The vulnerability affects the Easy Appointments WordPress plugin through version 3.12.26.
What unauthorized action can a user with Subscriber role perform by exploiting this vulnerability?
A user with Subscriber-level access can read all appointment bookings on the site due to insufficient capability checks on the REST endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.