CVE-2026-14827 - Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter
CVE ID :CVE-2026-14827
Published : July 27, 2026, 6 a.m. | 51 minutes ago
Description :The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 27, 2026, 6 a.m. | 51 minutes ago
Description :The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...