
CVE-2026-1252 The Events Listing Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Event URL' parameter in all versions up to, and including, 1.3.4 du… https://www.cve.org/CVERecord?id=CVE-2026-1252
Post summary
The Events Listing Widget plugin for WordPress (up to 1.3.4) has a stored XSS flaw in the Event URL parameter, as identified by CVE‑2026‑1252.

