PatchSiren

joedolson CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM joedolson CVE published 2026-09-09

CVE-2026-77187

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes in all versions up to, and including, 3.8.3. This vulnerability allows authenticated attackers with contributor-level access to inject arbitrary web scripts, potentially leading to user session hijacking or unauthorized actions on pages that will execut [truncated]

HIGH joedolson CVE published 2026-07-08

CVE-2026-6854

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Unauthenticated attackers can append additional SQL queries into existing queries to extract [truncated]