Junglewise Threat Intelligence

CVE-2026-14481: Equalize Digital Accessibility Checker Stored XSS in html parameter

CVE-2026-14481 · Severity: medium · CVSS 6.4 · Published 2026-07-23

Technologies: Equalize Digital Accessibility Checker. Vendors: Equalize Digital.

Executive brief

The Equalize Digital Accessibility Checker plugin for WordPress, which helps websites maintain legal accessibility compliance, contains a security flaw. An attacker with basic contributor-level access can inject malicious scripts into website pages. These scripts will automatically run in the browser of any user who visits the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The Equalize Digital Accessibility Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'html' parameter. The vulnerability is accessible via the REST API endpoint `/accessibility-checker/v1/post-scan-results/{id}`, which only requires the `edit_post` capability. Authenticated attackers with contributor-level access or higher can exploit this to inject arbitrary web scripts. These scripts are stored and will execute in the context of any user's browser session when they view the compromised post or page. The issue affects all versions up to and including 1.46.0.

Affected products

  • Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance <= 1.46.0

Timeline

  • 2026-07-23: disclosed: CVE published by Wordfence and NVD

References

Related threats