Impact
The My Calendar plugin for WordPress contains a stored cross‑site scripting vulnerability in all versions up to 3.8.3. The flaw exists in the short‑code "fallback" attribute, which is not properly sanitized or escaped when saved. An attacker with contributor‑level access can embed hex‑encoded payloads such as \x3cscript\x3e, which are treated as literal backslash sequences by wp_kses_post and later resolved to real HTML tags by shortcode_parse_atts() during rendering. This allows the attacker to inject arbitrary scripts that will run whenever a page containing the affected shortcode is viewed, enabling session hijacking, defacement, or further exploitation of other vulnerabilities. The impact is a persistent client‑side compromise with potential credential theft or malicious code execution in the context of the logged‑in user.
Affected Systems
The vulnerability affects the "My Calendar – Accessible Event Manager" plugin for WordPress, with all releases up to and including version 3.8.3. Any WordPress site running any of these affected versions is at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate risk. EPSS data is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitability requires an authenticated contributor‑level account that can create or edit content containing the shortcode. Once the payload is stored, it is executed on every page render that includes the shortcode, which makes the attack vector primarily application‑level. Although no public exploit has been documented, the combination of privileged access and persistent storage makes this vulnerability a significant risk for exposed sites.
OpenCVE Enrichment