Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-14225

LOW NVD
CVSS Score 2.7
Severity LOW
Published Aug 06, 2026
Vendor unknown

Description

The Easy Appointments WordPress plugin through 3.12.26 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary registered shortcodes.

References