Cross-site Scripting Flaw in The Events Calendar Shortcode Plugin by Brian Hogg
CVE-2026-24988
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 February 2026
What is CVE-2026-24988?
The Events Calendar Shortcode & Block plugin, developed by Brian Hogg, contains a vulnerability that allows for stored Cross-site Scripting (XSS). This occurs due to improper neutralization of user input when generating web pages. Attackers could leverage this flaw to inject malicious scripts into web pages that target users, potentially leading to unauthorized actions, data theft, or session hijacking. Users of affected versions should implement security measures and update their plugins promptly to mitigate this risk.
Affected Version(s)
The Events Calendar Shortcode & Block 0 <= 3.1.1