CVE-2026-14188 - CERT CVE
ID CVE-2026-14188
Sažetak The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users with contributor-level access to read every stored customer's personal information.
Reference
CVSS
Base: 2.7
Impact: 1.4
Exploitability:1.2
Pristup
VektorSloženostAutentikacija
NETWORK LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
LOW NONE NONE
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Zadnje važnije ažuriranje 10-08-2026 - 13:17
Objavljeno 30-07-2026 - 06:24