rootpwn

medium · CVSS v3 6.5 · EPSS 0.0027

CVE-2026-9232

The Easy Appointments plugin for WordPress up to version 3.12.27 contains a sensitive information exposure vulnerability in its AJAX handlin

Overview

The Easy Appointments plugin for WordPress up to version 3.12.27 contains a sensitive information exposure vulnerability in its AJAX handling functionality. This flaw allows authenticated attackers with low-level contributor privileges to access and extract the complete customer dataset. Consequently, sensitive personally identifiable information can be exfiltrated without proper authorization controls.

Description

The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses.

Impact

This vulnerability impacts the confidentiality of user data stored in the database, specifically targeting the ea_customers table. Organizations utilizing the affected plugin risk unauthorized exposure of customer personally identifiable information, including names, emails, phone numbers, and physical addresses. Integrity and availability remain unaffected, but privacy and compliance obligations are compromised for all affected customers.

Remediation

Upgrade the Easy Appointments plugin to the latest patched version beyond 3.12.27 as soon as the vendor provides a security update. Temporarily restrict contributor-level user registrations and review permissions if patching is delayed. Audit database access logs and monitor for anomalous queries targeting customer data tables.

Risk context

The vulnerability carries a medium CVSS score of 6.5, indicating a moderate technical severity. The current EPSS score is 0.0027, suggesting a low observed likelihood of exploitation in the wild, though internal privilege escalation or misuse by malicious contributors remains a viable risk.

Affected products

  • Easy Appointments plugin for WordPress

Scores

Severity
medium
CVSS v2
6.8
CVSS v3
6.5
CVSS v4
EPSS
0.0027

wordpress plugin information-disclosure cve defensive-analysis pii

← All CVEs