CVE-2026-84740

CVE-2026-84740 published: The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering context, allowing unauthenticated users to execute arbitrary shortcodes registered on th...

View full NVD advisory → ← Back to CVE watch