Shortcode Execution Vulnerability in Easy Appointments Plugin by WordPress
CVE-2026-14225
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-14225?
The Easy Appointments WordPress plugin, up to version 3.12.26, is affected by a flaw in its handling of shortcode input. This vulnerability arises from insufficient validation during a block-rendering process, where the plugin only checks the first tag of a supplied string against a predefined allowlist but fails to validate the entire string properly. This oversight allows users with contributor-level access to execute arbitrary registered shortcodes, potentially leading to unauthorized actions and compromising the security of the site.
Affected Version(s)
Easy Appointments 0 <= 3.12.26
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved