SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14827

MEDIUM · CVSS 6.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The Calendar WordPress plugin prior to version 1.3.18 is vulnerable due to improper escaping of user-supplied event fields, enabling users with Contributor roles to inject malicious JavaScript into HTML attributes. This could lead to cross-site scripting (XSS) attacks, impacting the security of users viewing the calendar on public-facing pages. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-14827
Severity
MEDIUM
CVSS
6.8
EPSS
0.23%
WordPress Java

Original NVD Description

The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.