Impact
The Events Calendar Shortcode & Block plugin for WordPress is vulnerable to a stored Cross‑Site Scripting flaw in the ecs‑list‑events shortcode message attribute. An attacker with contributor‑level or higher privileges can embed arbitrary JavaScript that runs whenever a page containing the injected shortcode is displayed.
Affected Systems
The flaw affects the The Events Calendar Shortcode & Block plugin developed by Brian Hogg, in all versions up to and including 3.1.2.
Risk and Exploitability
The severity score is CVSS 6.4, indicating moderate risk, and the computed EPSS score is less than 1%, suggesting a low probability of exploitation at present. It is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers must first gain authenticated access with at least contributor rights and then supply a crafted shortcode to store the malicious payload.
OpenCVE Enrichment