Just posting here in case someone at cal.com cares - not that updates to this are a thing, but yea:
Security vulnerability in Cal.com plugin (CVE-2025-31604)
Plugin: Cal.com (<= 1.0.0)
Vulnerability: Authenticated Stored Cross-Site Scripting (XSS)
CVE: CVE-2025-31604
Severity: Medium (CVSS 6.5)
Details: Improper neutralization of script-related HTML tags (e.g. <, "), potentially exploitable by users with Contributor role or higher.
As far as we can tell, the issue is still unfixed. Could you confirm whether a patch is in development or planned?
- that's a pickup from the support ticket in WP plugin repo.