alextselegidis
Web & CMS Pluginsindividual-dev
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting alextselegidis.
- CVE-2026-73529Plainpad Missing Rate Limiting via POST /v1/sessions5.3
- CVE-2026-55651Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure7.1
- CVE-2026-52841Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync3.1
- CVE-2026-52840Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network2.7
- CVE-2026-52839Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass3.3
- CVE-2026-52838Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS2.6
- CVE-2026-42562Plainpad: Privilege Escalation via Writable Admin Field in Profile Update (Access Control)8.3
- CVE-2026-23622CSRF Protection Bypass: Sensitive endpoints accept GET requests, enabling admin account takeover8.8
- CVE-2025-31828WordPress Easy!Appointments plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability4.3
- CVE-2024-0698Easy!Appointments <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
- CVE-2023-3700Authorization Bypass Through User-Controlled Key in alextselegidis/easyappointments6.3
- CVE-2023-3568Open Redirect in alextselegidis/easyappointments6.3
- CVE-2023-2105Session Fixation in alextselegidis/easyappointments8.8
- CVE-2023-2102Cross-site Scripting (XSS) - Stored in alextselegidis/easyappointments4.8
- CVE-2023-2104Improper Access Control in alextselegidis/easyappointments5.4