Security Advisory

CVE-2026-14225

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-06 17:00:54
Last updated 2026-08-07 14:06:50
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Easy Appointments WordPress plugin through 3.12.26 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary registered shortcodes.