WordPress · Easyappointments · CVE-2026-87965
**Name of the Vulnerable Software and Affected Versions**
Easy Appointments versions prior to 4.0.2.2
**Description**
The plugin fails to use an unguessable token to authorize appointment cancellation and confirmation actions via mail-links. The token is derived from a hardcoded source-embedded salt and the appointment's creation timestamp. Consequently, unauthenticated attackers who can determine or guess the timestamp can cancel or confirm arbitrary appointments.
**Recommendations**
Update to version 4.0.2.2 or later.