What the vulnerability does
01Description
The Easy Appointments WordPress plugin through 3.12.26 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary registered shortcodes.
Explanation of Vulnerability in Simple Terms
02Summary
Easy Appointments versions up to 3.12.26 contain a low-severity information disclosure vulnerability. An authenticated administrator can read limited sensitive data through the application. The vulnerability requires high-level privileges and does not affect data integrity or availability. Update to a version newer than 3.12.26 to remediate.
What an attacker can do
03Attacker Capabilities
Read limited sensitive information from the application.
Potential impact on your site
04Site Impact
Administrators with malicious intent could view restricted data, but site functionality and data integrity remain unaffected.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the Easy Appointments installation.
Key dates
06Disclosure timeline
August 6, 2026
CVE published