GHSA-m6cm-g8vp-fpwmMediumCVSS 6.5

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all...

Published
September 19, 2026
Last Modified
September 19, 2026

🔗 CVE IDs covered (1)

📋 Description

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses.

🔗 References (10)