
CVE-2026-0556 The XO Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xo_event_field' shortcode in all versions up to, and including… https://www.cve.org/CVERecord?id=CVE-2026-0556
Post summary
The post announces that the XO Event Calendar plugin for WordPress is vulnerable to stored XSS through a specific shortcode, referencing the CVE record for further detail.
