{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/easy-appointments-plugin--3.12.28/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-8789"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Easy Appointments plugin (\u003c 3.12.28)"],"_cs_severities":["high"],"_cs_tags":["wordpress","plugin","vulnerability","data-modification"],"_cs_type":"advisory","_cs_vendors":["WordPress","Easy Appointments"],"content_html":"\u003cp\u003eThe Easy Appointments plugin for WordPress, in versions up to and including 3.12.27, is susceptible to an unauthorized data modification vulnerability, identified as CVE-2026-8789. This critical flaw stems from a missing capability check and lack of nonce verification within the \u003ccode\u003eea_delete_multiple_connections\u003c/code\u003e AJAX action. This design oversight enables authenticated attackers, requiring only Contributor-level access or higher on a WordPress site, to arbitrarily delete connection records stored in the \u003ccode\u003ewp_ea_connections\u003c/code\u003e database table. The successful exploitation of this vulnerability directly disrupts the plugin's core booking functionalities, potentially causing service interruptions and data loss for organizations relying on Easy Appointments for scheduling and client management. The vulnerability could lead to significant operational challenges and impact data integrity.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains authenticated access to a WordPress site with at least Contributor-level privileges.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a specific AJAX POST request targeting the \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eThe request includes the \u003ccode\u003eaction=ea_delete_multiple_connections\u003c/code\u003e parameter and specifies the \u003ccode\u003econnection_ids\u003c/code\u003e to be deleted.\u003c/li\u003e\n\u003cli\u003eThe attacker either omits the \u003ccode\u003e_wpnonce\u003c/code\u003e parameter or provides an invalid one.\u003c/li\u003e\n\u003cli\u003eDue to the missing capability check, the plugin fails to properly verify the attacker's authorization level for this action.\u003c/li\u003e\n\u003cli\u003eConcurrently, the missing nonce verification allows the request to bypass Cross-Site Request Forgery (CSRF) protection.\u003c/li\u003e\n\u003cli\u003eThe plugin's vulnerable \u003ccode\u003eea_delete_multiple_connections\u003c/code\u003e function executes, leading to the deletion of specified records from the \u003ccode\u003ewp_ea_connections\u003c/code\u003e database table.\u003c/li\u003e\n\u003cli\u003eThe core booking functionality of the Easy Appointments plugin is disrupted, resulting in data modification and potential service outage.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-8789 allows authenticated attackers to delete critical connection records within the \u003ccode\u003ewp_ea_connections\u003c/code\u003e database table. This direct data modification disrupts the core booking functionality provided by the Easy Appointments plugin. Organizations using affected versions could face significant operational challenges, including loss of scheduling data, client booking information, and potential service interruptions. While the number of affected organizations is not specified, any entity running the Easy Appointments plugin on WordPress versions up to 3.12.27 is at risk. The vulnerability has a CVSS v3.1 Base Score of 8.1 (High), underscoring its potential for severe impact on data integrity and availability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-8789 immediately by updating the Easy Appointments plugin to version 3.12.28 or later.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule in this brief to your SIEM and tune for your environment to detect anomalous requests.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous or excessive POST requests to \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e with \u003ccode\u003eaction=ea_delete_multiple_connections\u003c/code\u003e originating from unusual user agents or IP addresses, particularly for users with lower privileges.\u003c/li\u003e\n\u003cli\u003eRegularly back up your WordPress database, especially the \u003ccode\u003ewp_ea_connections\u003c/code\u003e table, to facilitate recovery in case of data modification.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T15:20:36Z","date_published":"2026-07-24T15:20:36Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-8789-easy-appointments/","summary":"The Easy Appointments plugin for WordPress, in versions up to and including 3.12.27, is vulnerable to unauthorized data modification due to a missing capability check and nonce verification on the `ea_delete_multiple_connections` AJAX action, allowing authenticated attackers with Contributor-level access or higher to delete arbitrary connection records and disrupt core booking functionality.","title":"CVE-2026-8789: Easy Appointments WordPress Plugin Data Modification Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-8789-easy-appointments/"}],"language":"en","title":"CraftedSignal Threat Feed - Easy Appointments Plugin (\u003c 3.12.28)","version":"https://jsonfeed.org/version/1.1"}