CVE-2026-61946

MEDIUM

WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-61946. PoCs published by Rat5ak.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-61946, an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in the Easy Appointments WordPress plugin. The exploit allows attackers to overwrite existing appointment records by manipulating the 'id' parameter in the reservation endpoint.

Description

Unauthenticated Insecure Direct Object References (IDOR) in Easy Appointments <= 3.12.27 versions.

Exploits (1)

github WORKING POC
by Rat5ak · shellpoc
https://github.com/Rat5ak/CVE-2026-61946-Easy-Appointments-IDOR

This repository contains a functional proof-of-concept exploit for CVE-2026-61946, an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in the Easy Appointments WordPress plugin. The exploit allows attackers to overwrite existing appointment records by manipulating the 'id' parameter in the reservation endpoint.

Classification
Working Poc 99%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Easy Appointments WordPress plugin <= 3.12.27
No auth needed
Prerequisites: Knowledge of a valid appointment ID · Valid location, service, worker IDs, and an open time slot
mistral-large-3 · analyzed Jul 25, 2026 Full analysis →

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 14.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
Easy Appointments/Easy Appointments < 3.12.27
Published Jul 23, 2026
Tracked Since Jul 23, 2026