CVE-2026-14225
LOW
NVD
CVSS Score
2.7
Severity
LOW
Published
Aug 06, 2026
Vendor
unknown
Description
The Easy Appointments WordPress plugin through 3.12.26 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary registered shortcodes.