What is CVE-2026-14225?
The Easy Appointments WordPress plugin up to version 3.12.26 does not properly validate shortcode input, allowing users with contributor-level access to execute unauthorized shortcodes by bypassing the allowlist check. The plugin should be immediately updated to the latest version.
Azərbaycanca: Easy Appointments WordPress plaginin 3.12.26 versiyasına qədər olan versiyalarında qısa kod daxiletməsinin düzgün yoxlanılmaması aşkarlanıb. Bu zəiflik contributor səviyyəli istifadəçilərə icazə siyahısından yan keçərək təhlükəli qısa kodlar icra etməyə imkan verir. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the Easy Appointments plugin are affected by this shortcode injection vulnerability?
All versions up to 3.12.26 are affected.
What user access level is required to exploit this vulnerability?
Contributor-level user access is sufficient.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.