CVE-2026-14827: Unknown Calendar

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.

Affected products

  • Unknown Calendar: before 1.3.18 (fixed in 1.3.18)

Published 2026-07-27. Last modified 2026-07-27.