Skip to content

Known CVE

Easy Appointments <= 3.12.21 - Information Disclosure

Easy Appointments WordPress plugin <= 3.12.21 contains a sensitive information exposure caused by an unauthenticated REST API endpoint /wp-json/wp/v2/eablocks/ea_appointments/ registered with permission_callback allowing unrestricted access, letting unauthenticated attackers extract sensitive customer appointment data.

CVE-2026-2262

High2026CVSS 7.5CWE-284

cve2026 · wordpress · wp · wp-plugin · exposure · easy-appointments

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website