You can use the CSRF vulnerability to add/delete Occasions. It is also possible to enter JavaScript in occ_content1 parameter when occ_type1=1 .
Think this is a feature not a bug, anyway because of the CSRF vulnerability this can be used to execute arbitrary JavaScript in the front-end area
(shortcode = [Occasions]).
PoC will add an alert in the front-end area.
Note: check occ_startdate1 and occ_enddate1 and set them appropriate.