The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary connection records from the `wp_ea_connections` table, disrupting the plugin's core booking functionality.
We have discovered 583 live websites that are affected by CVE-2026-8789.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 583 live websites (100% of Easy Appointments install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 49 versions ( 100% of all versions) |
| 164 websites | |
| 63 websites | |
| 48 websites | |
| 30 websites | |
| 28 websites | |
| 21 websites | |
| 20 websites | |
| 20 websites | |
| 19 websites | |
| 15 websites |
| .com | 234 websites |
| .de | 40 websites |
| .nl | 26 websites |
| .org | 24 websites |
| .co.uk | 23 websites |
| .it | 14 websites |
| .fr | 14 websites |
| .ca | 13 websites |
| .com.au | 13 websites |
| .se | 9 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******************.fr | **,*** | ||
| ***********.com | ***,*** | ||
| ****************.com | *,***,*** | ||
| ******.com | *,***,*** | ||
| *******.****.ua | *,***,*** | ||
| ****.at | *,***,*** | ||
| ***************.it | *,***,*** | ||
| ************************.de | *,***,*** | ||
| ********.***.sg | *,***,*** | ||
| **********.be | *,***,*** |
FAQ