The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.

Project Subscriptions

Vendors Products
Calendar Subscribe
Calendar Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Calendar
Calendar calendar
Wordpress
Wordpress wordpress
Vendors & Products Calendar
Calendar calendar
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.
Title Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-27T17:39:03.012Z

Reserved: 2026-07-06T08:51:22.216Z

Link: CVE-2026-14827

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-27T15:23:05Z

Weaknesses

No weakness.