Undefined · Undefined · CVE-2026-14223
**Name of the Vulnerable Software and Affected Versions**
Easy Appointments WordPress plugin versions prior to 3.12.28
**Description**
Insufficient verification of ownership or capability when returning stored customer details allows users with subscriber-level access to read personal information of any customer by iterating an identifier.
**Recommendations**
Update the plugin to version 3.12.28 or later.