Junglewise Threat Intelligence

CVE-2026-2387: WordPress Event Organiser Stored XSS in eo_events shortcode

CVE-2026-2387 · Severity: medium · CVSS 6.4 · Published 2026-07-01

Executive brief

The Event Organiser plugin for WordPress, which is used to manage and display event calendars, contains a security flaw that allows users with contributor-level access to inject malicious scripts into website pages. These scripts execute automatically whenever a visitor views the affected page, potentially leading to unauthorized actions or data theft. This vulnerability impacts all versions of the plugin up to 3.12.9.

Technical details

The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to improper neutralization of input in the 'eo_events' shortcode. Specifically, the 'no_events' attribute accepts attacker-controlled content which is rendered in event list templates without adequate output escaping. An authenticated attacker with Contributor-level permissions or higher can exploit this to inject arbitrary web scripts. These scripts are stored on the server and execute in the context of any user's browser who visits the compromised page. The issue is present in all versions up to 3.12.9 and has been addressed in subsequent updates.

Affected products

  • stephenharris Event Organiser up to, and including, 3.12.9

Timeline

  • 2026-07-01: advisory: NVD publication date
  • 2026-07-01: disclosed: Wordfence advisory published

References