Stored Cross-Site Scripting in My Calendar Plugin for WordPress
CVE-2026-2355
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 March 2026
What is CVE-2026-2355?
The My Calendar β Accessible Event Manager plugin for WordPress has a vulnerability that allows authenticated users with Contributor-level access and above to exploit the template attribute of the [my_calendar_upcoming] shortcode. This vulnerability arises from improper handling of user-supplied values in the mc_draw_template() function, which fails to fully sanitize input during rendering. As a result, attackers can inject arbitrary web scripts into pages, which will execute whenever a user accesses those pages, compromising the security of affected sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
My Calendar β Accessible Event Manager * <= 3.7.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved