Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Sensitive Customer Information Exposure via ea_get_customers_ajax AJAX Action
Published Sep 19, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.47%
Description
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses.
Affected products
-
- Version 0StatusaffectedConstraints<=3.12.27
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Easyappointments | Easy Appointments | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.22/src/ajax.php#L115
- https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.22/src/ajax.php#L183
- https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.22/src/ajax.php#L2656
- https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.25/src/ajax.php#L115
- https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.25/src/ajax.php#L183
- https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.25/src/ajax.php#L2656
- https://plugins.trac.wordpress.org/changeset/3595856
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6b9322d5-afa0-4f38-b5df-2344310f4119?source=cve
Change history (0)
No recorded changes yet.