CVE-2024-38678
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Calendar.Online Calendar.Online / Kalender.Digital allows Stored XSS.This issue affects Calendar.Online / Kalender.Digital: from n/a through 1.0.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in WordPress Calendar.Online plugin up to 1.0.8 allows attackers to inject malicious scripts via improper input neutralization.
Vulnerability
Overview The vulnerability is a Stored Cross-Site Scripting (XSS) in the Calendar.Online / Kalender.Digital WordPress plugin, versions up to 1.0.8. It stems from improper neutralization of input during web page generation, allowing attackers to inject arbitrary HTML and JavaScript code that persists on the site [1].
Exploitation
Exploitation requires a privileged user with the ability to submit input that is not sanitized. The attacker can inject malicious scripts into the calendar functionality. When other users, including site visitors, access the affected page, the script executes. User interaction (e.g., clicking a link) may be needed for specific scenarios, but the stored nature means the payload is triggered automatically upon page load [1].
Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser. This can lead to session hijacking, redirection to malicious sites, defacement, or theft of sensitive information. The vulnerability could be exploited in mass campaigns to compromise numerous WordPress sites running the plugin [1].
Mitigation
The vendor has released version 1.0.9 which fixes the issue. Users are strongly advised to update immediately. Patchstack also provides a mitigation rule to block attacks until the update is applied. For sites unable to update immediately, a temporary workaround is to disable plugin functionality or seek assistance from a web developer [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=1.0.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.