CVE-2026-14827: Unknown Calendar
Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.
Affected products
- Unknown Calendar: before 1.3.18 (fixed in 1.3.18)
Published 2026-07-27. Last modified 2026-07-27.