EasyMe Connect
EasyMe Connect has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for EasyMe Connect has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nabil Irawan. EasyMe Connect is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-47609EasyMe Connect <= 3.0.3 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

EasyMe Connect
Author
easymebiz
Connects your EasyMe account and automatically embeds your custom javascript client code in your Web site. Grab and insert “Magic” EasyMe links from the links tab of any product and your booking modal will open as a layer on top of your own design. The plugin will automatically update your embedded code, so once connected, you can forget about it.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C