Impact
The My Calendar – Accessible Event Manager plugin for WordPress is susceptible to a stored cross‑site scripting flaw that arises from the lack of input sanitization and output escaping for the "before" and "after" shortcode attributes. An attacker who can authenticate to the site with contributor‑level privileges or higher can embed malicious JavaScript that will be persisted in the event data. When affected pages are viewed, the injected scripts run in the browsers of any visiting user, potentially allowing session hijacking, phishing, or the execution of arbitrary code within the victim’s session context.
Affected Systems
All WordPress installations running My Calendar up to and including version 3.8.3 are impacted. The vulnerability propagates to any site that employs the plugin’s shortcodes with the "before" or "after" attributes, regardless of site theme or additional plugins.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. EPSS data is not provided, so real‑world exploitation likelihood cannot be determined. The issue is not listed in the CISA KEV catalog, implying no known widespread exploitation. Exploitation requires authenticated access with contributor level or higher, so the attack vector is confined to the WordPress administrative interface; however, once the payload is stored, any site visitor can trigger the XSS execution.
OpenCVE Enrichment