Junglewise Threat Intelligence

CVE-2026-14827: Calendar WordPress plugin stored XSS in event_link parameter

CVE-2026-14827 · Severity: info · CVSS 6.8 · Published 2026-07-27

Vendors: Unknown.

Executive brief

The Calendar plugin for WordPress is vulnerable to a security flaw that allows users with basic 'Contributor' permissions to inject malicious scripts into the website. When other users or visitors view the calendar, these scripts can execute in their browsers, potentially leading to unauthorized actions or the theft of session information. This risk is particularly relevant for sites that allow multiple users to manage event content.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Calendar WordPress plugin due to insufficient output escaping of the 'event_link' field. An attacker with at least Contributor-level privileges can inject a malicious payload (e.g., using an 'onmouseover' event handler) into the Link field when creating or editing a calendar event. Because the plugin fails to sanitize this input before rendering it within an HTML attribute on public-facing pages, the script executes when a visitor interacts with the affected event. This issue is resolved in version 1.3.18.

Affected products

  • Unknown Calendar < 1.3.18

Timeline

  • 2026-07-06: disclosed
  • 2026-07-27: advisory: NVD publication date

References