Executive brief
The Events In City plugin for WordPress, which is used to display event listings, contains a security flaw that allows users with basic contributor permissions to inject malicious scripts into website pages. When other users or administrators visit these affected pages, the hidden scripts can execute automatically in their browsers. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive session information.
Technical details
The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping in the org_event_scode() function. Specifically, user-supplied attributes within the 'org-events' shortcode—including 'organizer_id', 'width', 'height', and 'layout'—are concatenated directly into HTML attributes without using the esc_attr() function. This allows authenticated attackers with contributor-level access or higher to inject arbitrary web scripts into pages. These scripts execute in the context of any user's browser who visits the compromised page. The vulnerability exists in all versions up to and including 3.0.
Affected products
- Events In City Events In City Up to and including 3.0
Timeline
- 2026-05-27: disclosed: Vulnerability published by Wordfence and NVD.