CVE-2026-14225 LOW

CVE-2026-14225: Easy Appointments <= 3.12.26 - Contributor+ Shortcode Allowlist Bypass

Vendor Unknown
Product Easy Appointments
Published August 6, 2026
Last update August 6, 2026

CVSS base score

2.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

The Easy Appointments WordPress plugin through 3.12.26 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary registered shortcodes.

Explanation of Vulnerability in Simple Terms

02Summary

Easy Appointments versions up to 3.12.26 contain a low-severity information disclosure vulnerability. An authenticated administrator can read limited sensitive data through the application. The vulnerability requires high-level privileges and does not affect data integrity or availability. Update to a version newer than 3.12.26 to remediate.

What an attacker can do

03Attacker Capabilities

Read limited sensitive information from the application.

Potential impact on your site

04Site Impact

Administrators with malicious intent could view restricted data, but site functionality and data integrity remain unaffected.

Conditions required to exploit

05Prerequisites

Attacker must have administrator-level access to the Easy Appointments installation.

Key dates

06Disclosure timeline

August 6, 2026 CVE published