CVE-2026-87966: Unknown Easy Appointments

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment identified by a request-supplied id, allowing unauthenticated attackers to overwrite, and through a follow-on cleanup delete, arbitrary appointments.

Affected products

  • Unknown Easy Appointments: from 4.0, before 4.0.2.2 (fixed in 4.0.2.2)

Published 2026-09-18. Last modified 2026-09-18.