Extension WordPress
Vulnérabilités My Calendar – Accessible Event Manager
Cette page rassemble les failles publiées pour My Calendar – Accessible Event Manager, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de My Calendar – Accessible Event Manager
19 fiches
My Calendar <= 3.7.8 – Unauthenticated SQL Injection via 'mc_auth' and 'mc_host' Parameters
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter…
*-3.7.8
3.7.9
08/07/2026
My Calendar <= 3.7.14 – Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14 via the 'vcal' parameter due to missing validation on a user controlled key.…
*-3.7.14
3.7.15
01/07/2026
My Calendar <= 3.7.9 – Authenticated (Custom+) Missing Authorization to Unauthorized Event Publication via 'event_approved' Parameter
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.9. This is due to the plugin not properly verifying that a user is authorized to…
*-3.7.9
3.7.10
13/05/2026
My Calendar – Accessible Event Manager <= 3.7.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template` attribute of the `[my_calendar_upcoming]` shortcode in all versions up to, and including, 3.7.3. This is due to the use…
*-3.7.3
3.7.4
03/03/2026
My Calendar <= 3.6.16 – Missing Authorization
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.6.16. This makes it possible for authenticated…
*-3.6.16
3.6.17
15/12/2025
My Calendar <= 3.4.23 – Authenticated (Admin+) Stored Cross-Site Scripting via Events
The My Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via events in all versions up to, and including, 3.4.23 due to insufficient input sanitization and output escaping on event dates. This makes it possible for…
*-3.4.23
3.4.24
11/02/2024
My Calendar <= 3.4.23 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The My Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.23 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-3.4.23
3.4.24
11/02/2024
My Calendar <= 3.4.21 – Unauthenticated SQL Injection
The My Calendar plugin for WordPress is vulnerable to [blind|generic|time-based] SQL Injection via the 'from' and 'to' parameters of the '/my-calendar/v1/events' rest route in all versions up to, and including, 3.4.21 due to insufficient escaping on the user…
*-3.4.21
3.4.22
26/11/2023
My Calendar <= 3.4.3 – Cross-Site Request Forgery
The My Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers…
*-3.4.3
3.4.4
20/01/2023
My Calendar <= 3.3.24.1 – Cross-Site Request Forgery
The My Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.24.1. This is due to missing or incorrect nonce validation on several functions handling the deletion of events and locations.…
*-3.3.24.1
3.3.25
03/01/2023
My Calendar <= 3.3.16 – Open Redirect
The My Calendar plugin for WordPress is vulnerable to Open Redirection in versions up to, and including, 3.3.16. This makes it possible for unauthenticated attackers to create links that look to be part of an affected site, but…
*-3.3.16
3.3.17
02/08/2022
My Calendar <= 3.3.16 – Administrator+ Stored Cross-Site Scripting
The My Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various parameters including the ‘street’ parameter in versions up to, and including, 3.3.16 due to insufficient input sanitization and output escaping. This makes it possible…
*-3.3.16
3.3.17
18/07/2022
My Calendar <= 3.2.17 – Subscriber+ Reflected Cross-Site Scripting
The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting…
*-3.2.17
3.2.18
01/11/2021
My Calendar <= 3.1.9 – Unauthenticated Cross-Site Scripting
The my-calendar plugin before 3.1.10 for WordPress has XSS.
*-3.1.9
3.1.10
30/04/2019
My Calendar <= 2.5.16 – Authenticated Stored Cross-Site Scripting
The My Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘event_time_label’ parameter in versions up to, and including, 2.6.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…
[*, 2.5.17)
2.5.17
04/04/2018
My Calendar <= 2.3.29 – Path Traversal to Remote Code Execution
The My Calendar plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.3.29 via the 'edit_my_calendar_styles' function in the 'my-calendar-styles.php' file. This allows unauthenticated attackers to overwrite the contents of all files the…
*-2.3.29
2.3.30
15/05/2015
My Calendar < 2.3.30 – Reflected Cross-Site Scripting
The My Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘value’ parameter in versions before 2.3.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
[*, 2.3.30)
2.3.30
15/05/2015
My Calendar < 2.3.10 – Reflected Cross-Site Scripting
The My Calendar plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 2.3.10 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a…
[*, 2.3.10)
2.3.10
20/04/2015
My Calendar < 1.10.5 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
[*, 1.10.5)
1.10.5
18/01/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.