Impact
The Private Google Calendars plugin for WordPress suffers from a missing capability check on the pgc_remove action, permitting authenticated users with Subscriber-level access or higher to reset the plugin’s settings. This flaw, identified as CWE‑862, allows attackers to modify configuration and potentially alter calendar visibility, access, or plugin behavior, thereby compromising the integrity of calendar data and the user experience.
Affected Systems
The vulnerability affects all installations of the Private Google Calendars plugin by michielve for WordPress with versions up to and including 20250811. The plugin’s settings reset functionality can be triggered by any user who has at least Subscriber authority within the WordPress site.
Risk and Exploitability
The CVSS score of 4.3 classifies the flaw as moderate severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The threat is not listed in CISA’s KEV catalog. Because the flaw requires an authenticated WordPress user, the attack vector is an internal, authenticated access path where the attacker must be capable of triggering the pgc_remove action. Given the dependency on user credentials and the lack of a public exploitation vector, the overall risk is moderate but exploitation probability remains low.
OpenCVE Enrichment