Vulnerability Description
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the full customer dataset from the ea_customers table, including personally identifiable information such as names, email addresses, mobile numbers, dates of birth, and physical addresses.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.22/src/aj
- https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.22/src/aj
- https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.22/src/aj
- https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.25/src/aj
- https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.25/src/aj
- https://plugins.trac.wordpress.org/browser/easy-appointments/tags/3.12.25/src/aj
- https://plugins.trac.wordpress.org/changeset/3595856
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6b9322d5-afa0-4f38-b5d
FAQ
What is CVE-2026-9232?
CVE-2026-9232 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.27 via the handle_customers_ajax. This makes it possible for authe...
How severe is CVE-2026-9232?
CVE-2026-9232 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-9232?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.