What is CVE-2026-19406?
A vulnerability in the Easy Appointments WordPress plugin before version 4.0.1 exposes all booking data via a REST endpoint. Users with contributor-level access can read all appointments, including customer names, schedules, and statuses, without authorization. Sites using this plugin should update to version 4.0.1 or later to mitigate the risk.
Azərbaycanca: Easy Appointments WordPress plaginindəki zəiflik (CVE-2026-19406) 4.0.1 versiyasından əvvəl mövcuddur. Bu boşluq 'contributor' səviyyəli istifadəçilərə REST endpoint vasitəsilə saytdakı bütün bron məlumatlarını (müştəri adları, qrafik, status) oxumağa imkan verir. Təsirə məruz qalan saytlar dərhal plaqini ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What user role can exploit the CVE-2026-19406 vulnerability in the Easy Appointments plugin?
Users with contributor-level access can exploit this vulnerability via the REST endpoint.
How can sites protect against CVE-2026-19406?
Sites should update the plugin to version 4.0.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.