CVE-2026-14221: Unknown Easy Appointments

Low severity, CVSS 3.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any authenticated user can obtain, allowing users with contributor-level access to read all customers' appointment details and to create, modify, and delete bookings.

Affected products

  • Unknown Easy Appointments: up to and including 4.0

Published 2026-07-30. Last modified 2026-08-10.