Description
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fallback' Shortcode Attribute in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass relies on hex-encoded shortcode attribute payloads (e.g. \x3cscript\x3e), which wp_kses_post cannot strip on save because they appear as literal backslash sequences rather than real HTML tags; WordPress core's shortcode_parse_atts() then calls stripcslashes() at render time, decoding the escapes into real angle brackets before they reach the unescaped sink.
Published: 2026-09-09
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via shortcode attribute
Action: Patch immediately
AI Analysis

Impact

The My Calendar plugin for WordPress contains a stored cross‑site scripting vulnerability in all versions up to 3.8.3. The flaw exists in the short‑code "fallback" attribute, which is not properly sanitized or escaped when saved. An attacker with contributor‑level access can embed hex‑encoded payloads such as \x3cscript\x3e, which are treated as literal backslash sequences by wp_kses_post and later resolved to real HTML tags by shortcode_parse_atts() during rendering. This allows the attacker to inject arbitrary scripts that will run whenever a page containing the affected shortcode is viewed, enabling session hijacking, defacement, or further exploitation of other vulnerabilities. The impact is a persistent client‑side compromise with potential credential theft or malicious code execution in the context of the logged‑in user.

Affected Systems

The vulnerability affects the "My Calendar – Accessible Event Manager" plugin for WordPress, with all releases up to and including version 3.8.3. Any WordPress site running any of these affected versions is at risk.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate risk. EPSS data is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitability requires an authenticated contributor‑level account that can create or edit content containing the shortcode. Once the payload is stored, it is executed on every page render that includes the shortcode, which makes the attack vector primarily application‑level. Although no public exploit has been documented, the combination of privileged access and persistent storage makes this vulnerability a significant risk for exposed sites.

Generated by OpenCVE AI on September 9, 2026 at 11:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the My Calendar plugin to version 3.8.4 or later.
  • If upgrading is not possible, limit contributor or author roles from editing shortcodes that use the fallback attribute, or remove the attribute from use entirely.
  • Configure a web‑application firewall such as Wordfence to detect and block script payloads in content, particularly backslash‑escaped XSS vectors.

Generated by OpenCVE AI on September 9, 2026 at 11:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Joedolson
Joedolson my Calendar – Accessible Event Manager
Wordpress
Wordpress wordpress
Vendors & Products Joedolson
Joedolson my Calendar – Accessible Event Manager
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Description The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fallback' Shortcode Attribute in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass relies on hex-encoded shortcode attribute payloads (e.g. \x3cscript\x3e), which wp_kses_post cannot strip on save because they appear as literal backslash sequences rather than real HTML tags; WordPress core's shortcode_parse_atts() then calls stripcslashes() at render time, decoding the escapes into real angle brackets before they reach the unescaped sink.
Title My Calendar <= 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fallback' Shortcode Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Joedolson My Calendar – Accessible Event Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-09T13:12:36.335Z

Reserved: 2026-08-20T16:36:39.274Z

Link: CVE-2026-77186

cve-icon Vulnrichment

Updated: 2026-09-09T13:12:26.182Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T04:19:55.880

Modified: 2026-09-09T15:33:34.467

Link: CVE-2026-77186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T22:45:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')