← WordPress Vulnerabilities
WordPress security by component

My Calendar

My Calendar creates and displays events in calendars, lists, and other configurable views on WordPress websites.

My Calendar (my-calendar) is a WordPress plugin with 14 published CVE records in this archive. The latest tracked vulnerability was published Sep 09, 2026; the highest published CVSS base score is 8.6.

Plugin slug: my-calendar

CVE-2026-77187: My Calendar permits stored scripts through before and after shortcode attributes

My Calendar through 3.8.3 inadequately sanitizes and escapes the before and after shortcode attributes. A Contributor or higher-privileged user can store script content in those attributes, which executes when another user views the rendered page.

PublishedSep 09, 2026
Known safe version3.8.4
Published vulnerabilities for my-calendar
Safe version
Sep 09, 2026 CVE-2026-77187
My Calendar permits stored scripts through before and after shortcode attributes
My Calendar through 3.8.3 inadequately sanitizes and escapes the before and after shortcode attributes. A Contributor or higher-privileged user can store script content in those attributes, which executes when another user views the rendered page.
3.8.4
CVE6.4
NVDPending
Sep 09, 2026 CVE-2026-77186
My Calendar decodes encoded fallback attributes into executable script content
My Calendar through 3.8.3 permits a Contributor or higher-privileged user to store hex-escaped script content in the fallback shortcode attribute. The escapes remain literal text during wp_kses_post filtering on save. At rendering, shortcode_parse_atts() calls stripcslashes(), decoding them into HTML before they reach an unescaped output, so scripts run when the page is viewed.
3.8.4
CVE6.4
NVDPending
Jul 02, 2026 CVE-2026-11896
My Calendar – Accessible Event Manager: Broken access control
My Calendar – Accessible Event Manager is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 3.7.14.
See mitigation notes
CVE5.3
NVDPending
May 14, 2026 CVE-2026-7525
My Calendar – Accessible Event Manager: A security weakness
My Calendar – Accessible Event Manager is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.7.9.
See mitigation notes
CVE4.3
NVDPending
Mar 04, 2026 CVE-2026-2355
My Calendar – Accessible Event Manager: Cross-site scripting
My Calendar – Accessible Event Manager is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Dec 09, 2025 CVE-2025-67592
My Calendar: A security weakness
My Calendar is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Apr 02, 2024 CVE-2024-1274
My Calendar: Cross-site scripting
My Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Mar 15, 2024 CVE-2024-25916
My Calendar: Cross-site scripting
My Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Nov 30, 2023 CVE-2023-6360
'My Calendar': SQL injection
'My Calendar' is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.6
NVD9.8
May 22, 2023 CVE-2023-23813
My Calendar: Cross-site request forgery
My Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Mar 15, 2023 CVE-2022-47427
My Calendar: Cross-site request forgery
My Calendar is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Nov 29, 2021 CVE-2021-24927
My Calendar: Cross-site scripting
My Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
Aug 28, 2019 CVE-2019-15713
My Calendar: Cross-site scripting
My Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jan 31, 2013 CVE-2012-6527
My Calendar: Cross-site scripting
My Calendar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD2.6