PT-2026-33528 · Easyappointments · Easyappointments

Published

2026-04-17

·

Updated

2026-04-18

·

CVE-2026-2262

CVSS v3.1

7.5

High

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the /wp-json/wp/v2/eablocks/ea appointments/ REST API endpoint. This is due to the endpoint being registered with 'permission callback' => ' return true', which allows access without any authentication or authorization checks. This makes it possible for unauthenticated attackers to extract sensitive customer appointment data including full names, email addresses, phone numbers, IP addresses, appointment descriptions, and pricing information.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-2262

Affected Products

Easyappointments