CVE-2026-14222

Published: Lug 30, 2026 Last Modified: Lug 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level access to delete the booking configuration and disable the booking system.

https://wpscan.com/vulnerability/5b481b5f-c994-46b9-9315-008aae77f785/