What is CVE-2026-14481?
This vulnerability affects the "Equalize Digital Accessibility Checker" plugin for WordPress. It allows Stored Cross-Site Scripting (XSS) via the 'html' parameter due to insufficient input sanitization and output escaping. All versions up to and including 1.46.0 are impacted, and users are strongly advised to update immediately.
Azərbaycanca: Bu boşluq "Equalize Digital Accessibility Checker" adlı WordPress plagininə təsir edir. 'html' parametri vasitəsilə Stored Cross-Site Scripting (XSS) hücumu mümkündür, çünki daxil edilən məlumatlar kifayət qədər təmizlənmir (input sanitization) və çıxış qaçırılmır (output escaping). Plaginin 1.46.0 və daha əvvəlki versiyaları risk altındadır, istifadəçilərə dərhal yeniləmə etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-14481 and what causes the vulnerability?
This vulnerability affects the "Equalize Digital Accessibility Checker" plugin. The issue is caused by insufficient input sanitization and output escaping on the 'html' parameter, which allows Stored XSS attacks.
Which versions are impacted by CVE-2026-14481 and what is recommended to users?
All versions of the plugin up to and including 1.46.0 are impacted. Users are strongly advised to update the plugin immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.