Executive brief
The ICS Calendar plugin for WordPress, which is used to display event calendars on websites, contains a security flaw that allows for reflected cross-site scripting. An attacker can trick a user into clicking a malicious link, which then executes unauthorized scripts in the user's browser. This could lead to the theft of sensitive session information or unauthorized actions being performed on behalf of the user.
Technical details
The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'htmltagtitle' parameter. The flaw exists within the unauthenticated 'wp_ajax_nopriv_r34ics_ajax' AJAX action, which merges attacker-controlled 'js_args' values over stored shortcode configurations without nonce verification. This allows the 'htmltagtitle' key to bypass standard shortcode allowlist checks. An unauthenticated remote attacker can exploit this by persuading a user to visit a specially crafted URL, resulting in the execution of arbitrary JavaScript in the context of the victim's browser session. The issue is fixed in versions following 12.0.9.
Affected products
- room34 ICS Calendar up to, and including, 12.0.9
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory
References
- https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.5.2/r34ics-ajax.php
- https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.5.2/r34ics-ajax.php
- https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.5.2/r34ics-ajax.php
- https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.5.2/templates/calendar-month.php
- https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.8.4/r34ics-ajax.php
- https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.8.4/r34ics-ajax.php
- https://plugins.trac.wordpress.org/browser/ics-calendar/tags/12.0.8.4/r34ics-ajax.php