CPE
The QuickCal WordPress plugin is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via custom field parameters, allowing attackers to execute arbitrary scripts in the context of site users.