CVE-2026-25465: WordPress CP Multi View Event Calendar plugin <= 1.4.36 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Multi View Event Calendar cp-multi-view-calendar allows Stored XSS.This issue affects CP Multi View Event Calendar : from n/a through <= 1.4.36.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Multi View Event Calendar cp-multi-view-calendar allows Stored XSS.This issue affects CP Multi View Event Calendar : from n/a through <= 1.4.37.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25465?
CVE-2026-25465 is classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2026-25465?
To mitigate CVE-2026-25465, you should update the CP Multi View Event Calendar plugin to version 1.4.36 or later.
What type of vulnerability is CVE-2026-25465?
CVE-2026-25465 is a Cross-Site Scripting (XSS) vulnerability that arises from improper input sanitization.
Which versions of the software are affected by CVE-2026-25465?
CVE-2026-25465 affects versions of the CP Multi View Event Calendar plugin up to and including 1.4.35.
What are the potential impacts of CVE-2026-25465?
The potential impacts of CVE-2026-25465 include unauthorized script execution in the context of a user's session, leading to potential data theft or manipulation.