WordPress · Easyappointments · CVE-2026-87966
**Name of the Vulnerable Software and Affected Versions**
Easy Appointments versions 4.0 through 4.0.2.1
**Description**
The plugin fails to perform ownership or authorization checks on the unauthenticated appointment-reservation endpoint. This allows unauthenticated attackers to overwrite or delete arbitrary appointments by providing a specific `id` in the request. This issue is an Insecure Direct Object Reference (IDOR), which occurs when an application provides direct access to objects based on user-supplied input without sufficient authorization.
**Recommendations**
Update Easy Appointments to version 4.0.2.2 or later.