CyberRota Analysis
AI-GeneratedThe Calendar WordPress plugin prior to version 1.3.18 is vulnerable due to improper escaping of user-supplied event fields, enabling users with Contributor roles to inject malicious JavaScript into HTML attributes. This could lead to cross-site scripting (XSS) attacks, impacting the security of users viewing the calendar on public-facing pages. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.