WordPress · Easyappointments · CVE-2026-11992
**Name of the Vulnerable Software and Affected Versions**
Easy Appointments versions prior to 3.12.28
**Description**
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with author-level access or higher can cancel all upcoming site-wide appointments by marking future appointments as abandoned. This is possible because the nonce (a unique token used to prevent cross-site request forgery) required for the cancellation request is displayed on the Appointments admin page, which is accessible to users with the `edit posts` capability.
**Recommendations**
Update Easy Appointments to version 3.12.28 or later.