Stored Cross-Site Scripting Vulnerability in The Events Calendar Shortcode & Block Plugin by WordPress
CVE-2026-1922
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 February 2026
What is CVE-2026-1922?
The Events Calendar Shortcode & Block plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping for the ecs-list-events shortcode's message attribute. This allows authenticated users with contributor-level permissions or higher to inject malicious scripts that execute when other users view the compromised pages. Users are advised to update to a secure version of the plugin to mitigate this risk.
Affected Version(s)
The Events Calendar Shortcode & Block 0 <= 3.1.2