WordPress Plugin Vulnerabilities

Easy Appointments <= 3.12.26 - Contributor+ Shortcode Allowlist Bypass

Description

The plugin does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary registered shortcodes.

Proof of Concept

Affects Plugins

No known fix

References

Miscellaneous

Original Researcher
Phyo Ko Ko
Submitter
Phyo Ko Ko
Verified
Yes

Timeline

Publicly Published
2026-07-08 (about 30 days ago)
Added
2026-07-01 (about 1 month ago)
Last Updated
2026-07-01 (about 1 month ago)

Other