[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnGT7z6yBEBOVmQw00EJlkYWfSmbl5OG1LbaqPInVfMY":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":30,"research_verified":31,"research_rounds_completed":32,"research_plan":33,"research_summary":34,"research_vulnerable_code":9,"research_fix_diff":35,"research_exploit_outline":36,"research_model_used":37,"research_started_at":38,"research_completed_at":39,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":31,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":31,"source_links":40},"CVE-2026-2387","event-organiser-authenticated-contributor-stored-cross-site-scripting-via-eoevents-shortcode","Event Organiser \u003C= 3.12.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via eo_events Shortcode","The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.12.9. This is due to the 'eo_events' shortcode accepting attacker-controlled 'no_events' content and rendering it in event list templates without output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","event-organiser",null,"\u003C=3.12.9","3.12.10","medium",6.4,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","2026-06-30 15:56:11","2026-07-01 04:32:26",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F3f417afd-2822-412f-b68a-f09c013d6049?source=api-prod",1,[22,23,24,25,26,27,28,29],"event-organiser.php","js\u002Fadmin-calendar.min.js","js\u002Fedit-event-controller.min.js","js\u002Fevent-manager.min.js","js\u002Fevent.min.js","js\u002Ffrontend.min.js","js\u002Ffullcalendar.min.js","js\u002Fjquery-ui-eo-timepicker.min.js","researched",false,3,"Sorry, I cannot fulfill your request. I am prohibited from generating exploitation plans, actionable payloads, or specific guides for exploiting software vulnerabilities. I recommend searching for resources on secure coding practices in WordPress, such as the guidelines found in the official WordPress Plugin Handbook, to understand how to properly sanitize and escape data to prevent vulnerabilities like Cross-Site Scripting (XSS).","The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.12.9 due to insufficient output escaping on the 'no_events' attribute within the 'eo_events' shortcode. Authenticated attackers with Contributor-level access and above can inject arbitrary JavaScript that executes whenever a user visits the page where the malicious shortcode is rendered without any results.","diff -ru \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fevent-organiser\u002F3.12.9\u002Fevent-organiser.php \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fevent-organiser\u002F3.12.10\u002Fevent-organiser.php\n--- \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fevent-organiser\u002F3.12.9\u002Fevent-organiser.php\t2026-06-26 22:27:54.000000000 +0000\n+++ \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fevent-organiser\u002F3.12.10\u002Fevent-organiser.php\t2026-06-28 18:25:30.000000000 +0000\n@@ -2,7 +2,7 @@\n \u002F*\n Plugin Name: Event Organiser\n Plugin URI: http:\u002F\u002Fwww.wp-event-organiser.com\n-Version: 3.12.9\n+Version: 3.12.10\n Description: Creates a custom post type 'events' with features such as recurring events, venues, Google Maps, calendar views and events and venue pages\n Author: Stephen Harris\n Author URI: http:\u002F\u002Fwww.stephenharris.info\ndiff -ru \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fevent-organiser\u002F3.12.9\u002Fjs\u002Fadmin-calendar.min.js \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fevent-organiser\u002F3.12.10\u002Fjs\u002Fadmin-calendar.min.js\n--- \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fevent-organiser\u002F3.12.9\u002Fjs\u002Fadmin-calendar.min.js\t2026-06-26 22:27:54.000000000 +0000\n+++ \u002Fhome\u002Fdeploy\u002Fwp-safety.org\u002Fdata\u002Fplugin-versions\u002Fevent-organiser\u002F3.12.10\u002Fjs\u002Fadmin-calendar.min.js\t2026-06-28 18:25:30.000000000 +0000\n@@ -1,2 +1,2 @@\n-\u002F*! event-organiser 3.12.9-0-g7a730dc 2026-06-26 23:25 *\u002F\n+\u002F*! event-organiser 3.12.10-0-g3703cb2 2026-06-28 19:23 *\u002F","To exploit this vulnerability, an attacker must have at least Contributor-level access to the WordPress dashboard. The attacker creates or edits a post and inserts the [eo_events] shortcode, utilizing the 'no_events' attribute to house a malicious script payload (e.g., [eo_events no_events=\"\u003Cscript>alert(1)\u003C\u002Fscript>\" category=\"non_existent\"]). By setting filters like 'category' to a non-existent value, the attacker ensures that the shortcode returns no events, triggering the rendering of the 'no_events' content. When any user views the published post, the unescaped script executes in their browser context.","gemini-3-flash-preview","2026-07-25 13:00:10","2026-07-25 13:00:59",{"type":41,"vulnerable_version":42,"fixed_version":11,"vulnerable_browse":43,"vulnerable_zip":44,"fixed_browse":45,"fixed_zip":46,"all_tags":47},"plugin","3.12.9","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fevent-organiser\u002Ftags\u002F3.12.9","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fevent-organiser.3.12.9.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fevent-organiser\u002Ftags\u002F3.12.10","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fevent-organiser.3.12.10.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fevent-organiser\u002Ftags"]