What is CVE-2026-8789?
The Easy Appointments plugin for WordPress, in versions up to 3.12.27, is vulnerable to unauthorized data modification via the `ea_delete_multiple_connections` AJAX action due to missing capability and nonce checks. This allows authenticated attackers to alter plugin data. Users should update to the latest patched version immediately.
Azərbaycanca: Easy Appointments WordPress plugin-inin 3.12.27-ə qədər olan versiyalarında `ea_delete_multiple_connections` AJAX əməliyyatı üzərində icazə yoxlaması və nonce doğrulamasının olmaması səbəbindən autentifikasiya olunmuş istifadəçilər məlumatları icazəsiz dəyişdirə bilər. Bu zəiflik pluginin iş məntiqinə təsir edir. İstifadəçilərə plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What security flaw exists in the `ea_delete_multiple_connections` AJAX action of the Easy Appointments plugin?
The action lacks capability and nonce checks, allowing authenticated users to modify plugin data without authorization.
How can I protect against CVE-2026-8789?
Update the Easy Appointments plugin to the latest version above 3.12.27 immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.