Title: Vulnerability reported
Last modified: August 14, 2026

---

# Vulnerability reported

 *  Resolved [wpmakenorg](https://wordpress.org/support/users/wpmakenorg/)
 * (@wpmakenorg)
 * [2 weeks, 2 days ago](https://wordpress.org/support/topic/vulnerability-reported-7/)
 * WordPress Easy Appointments plugin <= 4.0 – Broken Access Control vulnerability
 * Status: Protection Not Active

Viewing 5 replies - 1 through 5 (of 5 total)

 *  Plugin Support [Akshay A](https://wordpress.org/support/users/akshaycode1/)
 * (@akshaycode1)
 * [1 week, 5 days ago](https://wordpress.org/support/topic/vulnerability-reported-7/#post-18996123)
 * Hi,
 * Could you please share some more details about the issue?
 * If possible, a short video demonstrating the issue would be very helpful. This
   will allow us to better understand the problem and investigate it further.
 *  Thread Starter [wpmakenorg](https://wordpress.org/support/users/wpmakenorg/)
 * (@wpmakenorg)
 * [1 week, 4 days ago](https://wordpress.org/support/topic/vulnerability-reported-7/#post-18996586)
 * I received info via managewp – Does this link help? – [https://patchstack.com/database/wordpress/plugin/easy-appointments/vulnerability/wordpress-easy-appointments-plugin-3-12-26-contributor-appointment-data-disclosure-modification-vulnerability](https://patchstack.com/database/wordpress/plugin/easy-appointments/vulnerability/wordpress-easy-appointments-plugin-3-12-26-contributor-appointment-data-disclosure-modification-vulnerability)
 *  Plugin Support [Akshay A](https://wordpress.org/support/users/akshaycode1/)
 * (@akshaycode1)
 * [1 week, 3 days ago](https://wordpress.org/support/topic/vulnerability-reported-7/#post-18997976)
 * Hi,
 * We have already fixed this issue in our latest update, **version 4.0.1**. You
   can check in Changelog : [https://wordpress.org/plugins/easy-appointments/#developers](https://wordpress.org/plugins/easy-appointments/#developers)
 * Kindly update to the latest version, clear the cache, and give it another try.
   If you’re still facing any issues, please let us know, and we’ll be happy to 
   assist.
 *  Thread Starter [wpmakenorg](https://wordpress.org/support/users/wpmakenorg/)
 * (@wpmakenorg)
 * [1 week, 3 days ago](https://wordpress.org/support/topic/vulnerability-reported-7/#post-18998092)
 * Also in 4.0.1 same message through ManageWP
   Easy Appointments plugin <= 4.0.1–
   Broken Access Control vulnerability – Protection Not Active[](https://patchstack.com/database/vulnerability/easy-appointments/wordpress-easy-appointments-plugin-3-12-26-contributor-appointment-data-disclosure-modification-vulnerability?_a_id=350)
 * [https://patchstack.com/database/wordpress/plugin/easy-appointments/vulnerability/wordpress-easy-appointments-plugin-3-12-26-contributor-appointment-data-disclosure-modification-vulnerability](https://patchstack.com/database/wordpress/plugin/easy-appointments/vulnerability/wordpress-easy-appointments-plugin-3-12-26-contributor-appointment-data-disclosure-modification-vulnerability)
 *  Plugin Support [Akshay A](https://wordpress.org/support/users/akshaycode1/)
 * (@akshaycode1)
 * [1 day ago](https://wordpress.org/support/topic/vulnerability-reported-7/#post-19006175)
 * Hi,
 * The vulnerability has already been fixed in Easy Appointments **4.0.1**. The 
   message you are seeing in ManageWP is related to the **Patchstack** vulnerability
   database, which has not been updated yet to reflect the latest fix.
 * Once **Patchstack** updates their database on their end, the vulnerability status
   should be updated accordingly.
 * For now, please make sure you are running version **4.0.1** or later. No further
   action is required from your side regarding this **Patchstack** notification.

Viewing 5 replies - 1 through 5 (of 5 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fvulnerability-reported-7%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/easy-appointments/assets/icon-256x256.png?rev=1472759)
 * [Easy Appointments](https://wordpress.org/plugins/easy-appointments/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/easy-appointments/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/easy-appointments/)
 * [Active Topics](https://wordpress.org/support/plugin/easy-appointments/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/easy-appointments/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/easy-appointments/reviews/)

 * 8 replies
 * 2 participants
 * Last reply from: [Akshay A](https://wordpress.org/support/users/akshaycode1/)
 * Last activity: [1 day ago](https://wordpress.org/support/topic/vulnerability-reported-7/#post-19006175)
 * Status: resolved