CVE-2026-11992: CWE-862 Missing Authorization in easyappointments Easy Appointments
The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to cancel all upcoming appointments site-wide by marking every future appointment stored by the plugin as abandoned. The nonce required to authenticate the cancellation request is printed on the Appointments admin page, which is itself gated only by the edit_posts capability that Authors possess, making the nonce readily accessible to low-privileged users.
AI Analysis
Technical Summary
CVE-2026-11992 is an authorization bypass vulnerability (CWE-862) in the Easy Appointments WordPress plugin affecting all versions up to 3.12.27. The plugin fails to properly verify that a user is authorized to perform appointment cancellation actions. Authenticated users with author-level access or higher can use a nonce exposed on an admin page gated by the edit_posts capability to cancel all future appointments site-wide by marking them as abandoned. This vulnerability allows low-privileged users to perform actions beyond their intended permissions.
Potential Impact
The vulnerability allows authenticated users with author-level permissions to cancel all upcoming appointments across the site, potentially disrupting business operations or service scheduling. There is no direct confidentiality or availability impact reported, but the integrity of appointment data is compromised. The CVSS score is 4.3 (medium severity), reflecting low complexity and low privileges required, with no user interaction needed.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. Users should monitor the vendor's advisory for updates. As a temporary mitigation, restrict author-level user permissions or avoid granting edit_posts capability to untrusted users until a fix is released. Review user roles and capabilities to limit access to the affected admin pages. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-11992: CWE-862 Missing Authorization in easyappointments Easy Appointments
Description
The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with author-level access and above, to cancel all upcoming appointments site-wide by marking every future appointment stored by the plugin as abandoned. The nonce required to authenticate the cancellation request is printed on the Appointments admin page, which is itself gated only by the edit_posts capability that Authors possess, making the nonce readily accessible to low-privileged users.
CVSS v3.1
Score 4.3medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-11992 is an authorization bypass vulnerability (CWE-862) in the Easy Appointments WordPress plugin affecting all versions up to 3.12.27. The plugin fails to properly verify that a user is authorized to perform appointment cancellation actions. Authenticated users with author-level access or higher can use a nonce exposed on an admin page gated by the edit_posts capability to cancel all future appointments site-wide by marking them as abandoned. This vulnerability allows low-privileged users to perform actions beyond their intended permissions.
Potential Impact
The vulnerability allows authenticated users with author-level permissions to cancel all upcoming appointments across the site, potentially disrupting business operations or service scheduling. There is no direct confidentiality or availability impact reported, but the integrity of appointment data is compromised. The CVSS score is 4.3 (medium severity), reflecting low complexity and low privileges required, with no user interaction needed.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. Users should monitor the vendor's advisory for updates. As a temporary mitigation, restrict author-level user permissions or avoid granting edit_posts capability to untrusted users until a fix is released. Review user roles and capabilities to limit access to the affected admin pages. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-06-11T14:53:51.026Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a50b54868715ace4351b32f
Added to database: 07/10/2026, 09:03:04 UTC
Last enriched: 07/17/2026, 09:51:09 UTC
Last updated: 08/24/2026, 22:52:08 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.