Medium 5.3
2025-12-20< 2.0.1
CVE-2025-12898
Minimum safe version
2.0.1
Update to 2.0.1 or later to address 5 fixable vulnerabilities
CVE-2025-12898
CVE-2024-33640
Pretty Google Calendar < 1.6.0 - Authenticated(Contributor+) Stored Cross-Site Scripting via pretty_google_calendar shortcode
WordPress Pretty Google Calendar Plugin < 1.6.0 is vulnerable to Cross Site Scripting (XSS)
Pretty Google Calendar <= 1.5.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via pretty_google_calendar shortcode