cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forembed-calendly-scheduling embed-calendly-scheduling

Direction: ascending
Jun 07, 2024

Embed Calendly # CVE-2023-4995

CVE, Research URL

CVE-2023-4995

Application

Embed Calendly

Date
Oct 13, 2023
Research Description
The Embed Calendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'calendly' shortcode in versions up to, and including, 3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 3.7.
Status
vulnerable
Mar 30, 2026

Embed Calendly # CVE-2026-32411

CVE, Research URL

CVE-2026-32411

Application

Embed Calendly

Date
Mar 14, 2026
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simpma Embed Calendly embed-calendly-scheduling allows Stored XSS.This issue affects Embed Calendly: from n/a through <= 4.4.
Affected versions
max 4.4.
Status
vulnerable