CVE-2026-61946
MEDIUMWordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-61946. PoCs published by Rat5ak.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-61946, an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in the Easy Appointments WordPress plugin. The exploit allows attackers to overwrite existing appointment records by manipulating the 'id' parameter in the reservation endpoint.
Description
Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2026-61946, an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in the Easy Appointments WordPress plugin. The exploit allows attackers to overwrite existing appointment records by manipulating the 'id' parameter in the reservation endpoint.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L