CVE-2026-2427 | kazunii itsukaita Plugin up to 0.1.2 on WordPress Parameters day_from/day_to cross site scripting
A vulnerability classified as problematic has been found in kazunii itsukaita Plugin up to 0.1.2 on WordPress. This affects an unknown part of the component Parameters Handler. The manipulation of the argument day_from/day_to leads to cross site scripting.
This vulnerability is documented as CVE-2026-2427. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.