Tag
high
advisory
CVE-2026-8789: Easy Appointments WordPress Plugin Data Modification Vulnerability
1 rule 1 TTP 1 CVEThe Easy Appointments plugin for WordPress, in versions up to and including 3.12.27, is vulnerable to unauthorized data modification due to a missing capability check and nonce verification on the `ea_delete_multiple_connections` AJAX action, allowing authenticated attackers with Contributor-level access or higher to delete arbitrary connection records and disrupt core booking functionality.
Easy Appointments plugin
wordpress
plugin
vulnerability
data-modification
1r
1t
1c
high
advisory
Tandoor Recipes Unauthorized RecipeBook Modification Vulnerability (CVE-2026-35488)
2 rules 1 TTP 1 CVETandoor Recipes versions prior to 2.6.4 allow unauthorized modification and deletion of RecipeBooks due to a flaw in the CustomIsShared permission class which grants write access to shared users regardless of intended read-only permissions.
Tandoor Recipes
CVE-2026-35488
Unauthorized Access
Data Modification
2r
1t
1c