
CVE-2026-19406 The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, a… https://www.cve.org/CVERecord?id=CVE-2026-19406
Post summary
The text announces a vulnerability in the Easy Appointments plugin, noting the lack of user restrictions on a REST endpoint, but it does not provide PoC, exploit code, or patch information.

