medium · CVSS v3 6.5 · EPSS 0.0027
CVE-2026-9232
The Easy Appointments plugin for WordPress up to version 3.12.27 contains a sensitive information exposure vulnerability in its AJAX handlin
Overview
The Easy Appointments plugin for WordPress up to version 3.12.27 contains a sensitive information exposure vulnerability in its AJAX handling functionality. This flaw allows authenticated attackers with low-level contributor privileges to access and extract the complete customer dataset. Consequently, sensitive personally identifiable information can be exfiltrated without proper authorization controls.
Description
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses.
Impact
This vulnerability impacts the confidentiality of user data stored in the database, specifically targeting the ea_customers table. Organizations utilizing the affected plugin risk unauthorized exposure of customer personally identifiable information, including names, emails, phone numbers, and physical addresses. Integrity and availability remain unaffected, but privacy and compliance obligations are compromised for all affected customers.
Remediation
Upgrade the Easy Appointments plugin to the latest patched version beyond 3.12.27 as soon as the vendor provides a security update. Temporarily restrict contributor-level user registrations and review permissions if patching is delayed. Audit database access logs and monitor for anomalous queries targeting customer data tables.
Risk context
The vulnerability carries a medium CVSS score of 6.5, indicating a moderate technical severity. The current EPSS score is 0.0027, suggesting a low observed likelihood of exploitation in the wild, though internal privilege escalation or misuse by malicious contributors remains a viable risk.
Affected products
- Easy Appointments plugin for WordPress
Scores
- Severity
- medium
- CVSS v2
- 6.8
- CVSS v3
- 6.5
- CVSS v4
- —
- EPSS
- 0.0027