WordPress Plugin Vulnerabilities

Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter

Description

The plugin does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.

Proof of Concept

Affects Plugins

Fixed in 1.3.18

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Marcus Cornes
Submitter
Marcus Cornes
Verified
Yes

Timeline

Publicly Published
2026-07-06 (about 21 days ago)
Added
2026-07-06 (about 20 days ago)
Last Updated
2026-07-06 (about 20 days ago)

Other