{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awordpressquickcal/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:quickcal:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-15984"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["QuickCal (\u003c= 1.0.20)"],"_cs_severities":["high"],"_cs_tags":["wordpress","xss","cve-2026-15984"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe QuickCal plugin for WordPress, in versions up to and including 1.0.20, contains a security vulnerability (CVE-2026-15984) resulting from insufficient input sanitization and output escaping. This flaw allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) attacks by injecting arbitrary web scripts through custom field parameters. The vulnerability is exacerbated by the improper exposure of a security nonce used to protect the booked_add_appt AJAX action. This nonce is publicly embedded within the HTML source of any page utilizing the booking calendar shortcode. Because the nonce is easily retrievable by unauthenticated actors, they can successfully perform unauthorized actions and store malicious scripts that execute whenever a victim views the affected page.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability permits unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's session. This may lead to unauthorized data access, session hijacking, or the defacement of the affected WordPress site. Given the plugin's purpose, high-traffic booking pages are at particular risk, potentially exposing administrators and customers to credential theft or redirection to malicious sites.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the QuickCal plugin to the latest version (patch for 1.0.20 or later) as provided by the developer.\u003c/li\u003e\n\u003cli\u003eIf an update is not immediately available, disable the booking calendar shortcode on all public-facing pages to prevent the leakage of the booked_add_appt AJAX nonce.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for suspicious HTTP POST requests directed to the booked_add_appt AJAX endpoint.\u003c/li\u003e\n\u003cli\u003eImplement a robust Content Security Policy (CSP) that restricts script execution to trusted domains, mitigating the impact of potential XSS injections.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T07:30:16Z","date_published":"2026-09-05T07:30:16Z","id":"https://feed.craftedsignal.io/briefs/2026-09-quickcal-xss/","summary":"The QuickCal WordPress plugin is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via custom field parameters, allowing attackers to execute arbitrary scripts in the context of site users.","title":"Stored Cross-Site Scripting in WordPress QuickCal Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-quickcal-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wordpress:quickcal:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}