The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so unauthenticated attackers who know or guess that timestamp can cancel or confirm arbitrary appointments.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token from a hardcoded source-embedded salt and the appointment's creation timestamp, so unauthenticated attackers who know or guess that timestamp can cancel or confirm arbitrary appointments.
Title Easy Appointments < 4.0.2.2 - Unauthenticated Appointment Cancellation/Confirmation via Forgeable Email-Link Token
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T06:00:15.366Z

Reserved: 2026-09-09T17:46:04.630Z

Link: CVE-2026-87965

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-18T06:16:40.847

Modified: 2026-09-18T06:16:40.847

Link: CVE-2026-87965

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.