Junglewise Threat Intelligence

CVE-2026-77187: WordPress My Calendar Stored XSS in shortcode attributes

CVE-2026-77187 · Severity: medium · CVSS 6.4 · Published 2026-09-09

Vendors: Joe Dolson.

Executive brief

My Calendar is a popular WordPress plugin for managing and displaying events on websites. The plugin is vulnerable to stored cross-site scripting (XSS), which allows attackers with contributor-level access to inject malicious scripts into event pages. When other users view these pages, the injected scripts execute, potentially stealing credentials, defacing content, or compromising visitor data.

Technical details

The vulnerability is a Stored XSS flaw in the 'before' and 'after' shortcode attributes of the My Calendar plugin. The root cause is insufficient input sanitization and output escaping when processing these shortcode parameters. An authenticated attacker with contributor-level access or higher can inject arbitrary JavaScript into shortcode attributes, which is stored in the database and executed in the browsers of all users who view the affected pages. The vulnerability affects all versions up to and including 3.8.3. Patches are available in later versions as evidenced by sanitization commits in the plugin repository.

Affected products

  • Joe Dolson My Calendar – Accessible Event Manager up to and including 3.8.3

Timeline

  • 2026-09-09: disclosed

References