WordPress Plugin Vulnerabilities

Easy Appointments < 3.12.28 - Contributor+ Shortcode Allowlist Bypass

Description

The plugin does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with contributor-level access to execute arbitrary registered shortcodes.

Proof of Concept

Affects Plugins

Fixed in 3.12.28

References

Miscellaneous

Original Researcher
Phyo Ko Ko
Submitter
Phyo Ko Ko
Verified
Yes

Timeline

Publicly Published
2026-07-08 (about 1 month ago)
Added
2026-07-01 (about 1 month ago)
Last Updated
2026-08-10 (about 17 days ago)

Other