CVE-2026-55651: Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user t
Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users.
Using these hashes, an attacker can modify or delete appointments of other providers, resulting in an Appointments Takeover. Version 1.6.0 fixes the issue.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-55651
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-556510.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55651 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Easy!Appointments is a
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-14226: The Easy Appointments WordPress plugin through 3.12.26 does not require a sufficient capabilit…nvd · 2026-07-30
- mediumCVE-2026-14223: The Easy Appointments WordPress plugin through 3.12.26 does not verify ownership or capability…nvd · 2026-07-30
- lowCVE-2026-14222: The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonc…nvd · 2026-07-30
- lowCVE-2026-14221: The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in s…nvd · 2026-07-30
- lowCVE-2026-14188: The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capabili…nvd · 2026-07-30
- lowGHSA-996f-334j-67g7: Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — S…ghsa · 2026-07-29
More from NVD Recent CVEs
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01
- mediumCVE-2026-67354: guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in Re…2026-08-01
- mediumCVE-2026-67353: guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the Cook…2026-08-01
- highCVE-2026-67352: luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_…2026-08-01
- mediumCVE-2026-67344: ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYP…2026-08-01