Executive brief
ICS Calendar is a WordPress plugin used to display and manage calendar events from external sources. A security vulnerability in this plugin allows attackers to inject malicious scripts into the website, which are then executed in the browsers of other users. If a site administrator or visitor clicks a specially crafted link, the attacker could potentially steal session information, redirect users to malicious sites, or perform unauthorized actions on the website.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the ICS Calendar plugin for WordPress (versions <= 12.1.1) due to improper neutralization of user-supplied input during web page generation. The vulnerability allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a victim's browser session. Exploitation requires a user to interact with a malicious link or visit a crafted page (User Interaction: Required). The attack vector is network-based with low complexity, and the impact includes a scope change (S:C), potentially compromising the confidentiality and integrity of the user's session. The issue is resolved in version 12.1.1.1.
Affected products
- Room 34 Creative Services, LLC ICS Calendar <= 12.1.1
Timeline
- 2026-06-27: disclosed: Reported by Nguyen Ba Khanh to Patchstack
- 2026-07-10: advisory: Patchstack published advisory
- 2026-07-13: advisory: NVD published CVE record
- 2026-07-13: patched: Version 12.1.1.1 identified as patched version