AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-14225

LOW · CVSS 2.7 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The Easy Appointments plugin for WordPress versions up to 3.12.26 is vulnerable due to improper validation of shortcode input, allowing users with contributor-level access to execute arbitrary shortcodes. This could lead to unauthorized actions being performed on the site, potentially compromising its integrity. WordPress site administrators, particularly those using this plugin, should prioritize updating to mitigate the risk of exploitation.

CVE
CVE-2026-14225
Severity
LOW
CVSS
2.7
EPSS
0.23%
WordPress

Original NVD Description

The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary registered shortcodes.