CVE-2026-14827
MEDIUMCalendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter
Title source: cnaDescription
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/b2981b41-b712-43d9-a327-3a376346cec5/
Scores
CVSS v3
6.8
EPSS
0.0024
EPSS Percentile
14.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (1)
None/Calendar
< 1.3.18
Published
Jul 27, 2026
Tracked Since
Jul 27, 2026