Vendor
high
advisory
CVE-2026-8789: Easy Appointments WordPress Plugin Data Modification Vulnerability
1 rule 1 TTP 1 CVEThe Easy Appointments plugin for WordPress, in versions up to and including 3.12.27, is vulnerable to unauthorized data modification due to a missing capability check and nonce verification on the `ea_delete_multiple_connections` AJAX action, allowing authenticated attackers with Contributor-level access or higher to delete arbitrary connection records and disrupt core booking functionality.
Easy Appointments plugin
wordpress
plugin
vulnerability
data-modification
1r
1t
1c
high
advisory
Easy Appointments WordPress Plugin Sensitive Data Exposure
2 rules 1 TTP 1 CVEThe Easy Appointments WordPress plugin through version 3.12.21 exposes sensitive customer appointment data, including names, emails, phone numbers, and IP addresses, due to an improperly secured REST API endpoint.
Easy Appointments plugin
wordpress
plugin
sensitive-data-exposure
rest-api
2r
1t
1c