CVE-2026-14225: Easy Appointments <= 3.12.26 - Contributor+ Shortcode Allowlist Bypass
The Easy Appointments WordPress plugin through 3.12.26 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary registered shortcodes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14225?
The severity of CVE-2026-14225 is classified as low with a score of 2.7.
How do I fix CVE-2026-14225?
To fix CVE-2026-14225, update the Easy Appointments WordPress plugin to version 3.12.27 or later.
What impact does CVE-2026-14225 have on my site?
CVE-2026-14225 allows users with contributor-level access to bypass shortcode restrictions, potentially executing unauthorized actions.
Who is affected by CVE-2026-14225?
CVE-2026-14225 affects users of the Easy Appointments WordPress plugin version 3.12.26 and below.
Is my site vulnerable if I use Easy Appointments plugin?
Yes, if you are using version 3.12.26 or earlier of the Easy Appointments plugin, your site is vulnerable to CVE-2026-14225.