EasyMe Connect

EasyMe Connect has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).

The one issue recorded for EasyMe Connect has a vendor fix available, so running the current release closes it.

All of these findings were reported by Nabil Irawan. EasyMe Connect is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all EasyMe Connect vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2025-47609

EasyMe Connect <= 3.0.3 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
EasyMe Connect banner
Latestv3.0.4

EasyMe Connect

easymebiz

Author

easymebiz

5.0(1)
100/100
Last Updated
2026-05-21 (4mo ago)
Active Installs
500+
Downloads
13,624
Requires WP
5.3+
Requires PHP
7.0+
Tested up to
WP 7.0.4
Created
2017-04-19 (10y ago)

Connects your EasyMe account and automatically embeds your custom javascript client code in your Web site. Grab and insert “Magic” EasyMe links from the links tab of any product and your booking modal will open as a layer on top of your own design. The plugin will automatically update your embedded code, so once connected, you can forget about it.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C