CyberSec.Space Logo
Back to CVE Browser

CVE-2026-14827

N/A
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-07-27
Last Modified2026-07-27
Data SourcesNVD

Vulnerability Description

The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, allowing users with the Contributor role to inject arbitrary JavaScript that executes in the browser of anyone viewing the calendar.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities

CVE-2026-14827 Detail & Impact Analysis | CVSS Pending | Cyber-Sec.Space | Cyber-Sec.Space