Stored Cross-Site Scripting in My Calendar Plugin for WordPress
CVE-2026-2355
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 March 2026
What is CVE-2026-2355?
The My Calendar β Accessible Event Manager plugin for WordPress has a vulnerability that allows authenticated users with Contributor-level access and above to exploit the template attribute of the [my_calendar_upcoming] shortcode. This vulnerability arises from improper handling of user-supplied values in the mc_draw_template() function, which fails to fully sanitize input during rendering. As a result, attackers can inject arbitrary web scripts into pages, which will execute whenever a user accesses those pages, compromising the security of affected sites.
Affected Version(s)
My Calendar β Accessible Event Manager 0 <= 3.7.3