CyberRota Analysis
AI-GeneratedThe Easy Appointments plugin for WordPress versions up to 3.12.26 is vulnerable due to improper validation of shortcode input, allowing users with contributor-level access to execute arbitrary shortcodes. This could lead to unauthorized actions being performed on the site, potentially compromising its integrity. WordPress site administrators, particularly those using this plugin, should prioritize updating to mitigate the risk of exploitation.
Original NVD Description
The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary registered shortcodes.