PT-2026-95247 · WordPress · Easyappointments
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Easy Appointments versions prior to 4.0.2.2
Description
The plugin fails to use an unguessable token to authorize appointment cancellation and confirmation actions via mail-links. The token is derived from a hardcoded source-embedded salt and the appointment's creation timestamp. Consequently, unauthenticated attackers who can determine or guess the timestamp can cancel or confirm arbitrary appointments.
Recommendations
Update to version 4.0.2.2 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easyappointments