CVE-2026-14481

Equalize Digital Accessibility Checker <= 1.46.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'html' Parameter

The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' parameter in all versions up to, and including, 1.46.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to have the ability to edit a post, as the REST endpoint /accessibility-checker/v1/post-scan-results/{id} is guarded only by the edit_post capability on the target post.


We have discovered 3,928 live websites that are affected by CVE-2026-14481.

Run a Free Instant Scan




Affected Software

Product  Accessibility Checker
Category Wordpress Plugins
Vulnerable Domains3,928 live websites (100% of Accessibility Checker install base)
Vulnerable Versions
  • from 0 through 1.46
Vulnerable Versions Count34 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-14481
United States2,636 websites



Germany437 websites
GB116 websites
Spain105 websites
Italy90 websites
Canada82 websites
France62 websites
Poland49 websites
Austria38 websites
Netherlands27 websites

Website Distribution by TLD

Number of websites using CVE-2026-14481
.com1,764 websites
.org935 websites
.de331 websites
.net84 websites
.edu72 websites
.ca64 websites
.it55 websites
.co.uk43 websites
.at40 websites
.pl39 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-14481

Top websites that are affected by CVE-2026-14481. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.gov United States*,***
******.com United States*,***
***.***.edu United States*,***
*******.****.gov United States*,***
**************.org United States**,***
*****.com United States**,***
*****************.com United States**,***
****.********.edu United States**,***
*********.com United States**,***
**************.****************.com GB**,***
See full domain list

FAQ

CVE-2026-14481 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Accessibility Checker
A total of 3,928 websites have been identified as vulnerable to CVE-2026-14481, based on global website indexing conducted by WebTechSurvey.
The Accessibility Checker is affected by the CVE-2026-14481 vulnerability.
Accessibility Checker versions up to and including 1.46 are vulnerable to CVE-2026-14481.

References