Description
Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Cross Site Request Forgery.This issue affects Quick Event Calendar: from n/a through <= 1.4.9.
Published: 2025-06-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery in the WP Corner Quick Event Calendar plugin allows attackers to perform actions on behalf of an authenticated user without their consent. The flaw can lead to unauthorized modifications of calendar data such as creating, editing, or deleting events, potentially disrupting user schedules and compromising the integrity of the site’s content. This vulnerability is identified as CWE‑352. Based on the description, the attacker may be able to trigger the request by enticing the victim to visit a specially crafted URL.

Affected Systems

Vendors and affected products include WP Corner’s Quick Event Calendar plugin for WordPress, affecting all installations of version 1.4.9 or earlier. No specific operating system or platform constraints are listed.

Risk and Exploitability

An attacker would need to target a user that is logged into the WordPress site with sufficient privileges to change event data. The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% reflects a low likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog, suggesting that there is no known widespread exploitation. However, because the attack can be performed through standard HTTP requests, it remains feasible for a determined adversary, especially if account credentials are weak or compromised. Based on the description, the attacker may be able to trigger the request by enticing the victim to visit a specially crafted URL.

Generated by OpenCVE AI on May 2, 2026 at 08:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Quick Event Calendar plugin to any fixed release newer than 1.4.9.
  • If an update cannot be applied immediately, temporarily deactivate the plugin to prevent unauthorized modifications.
  • Ensure WordPress users have strong passwords and enable two‑factor authentication to reduce the risk of credential compromise, which can be used together with CSRF to gain access to the site.

Generated by OpenCVE AI on May 2, 2026 at 08:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17165 Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar allows Cross Site Request Forgery. This issue affects Quick Event Calendar: from n/a through 1.4.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar allows Cross Site Request Forgery. This issue affects Quick Event Calendar: from n/a through 1.4.9. Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Cross Site Request Forgery.This issue affects Quick Event Calendar: from n/a through <= 1.4.9.
Title WordPress Quick Event Calendar <= 1.4.9 - Cross Site Request Forgery (CSRF) Vulnerability WordPress Quick Event Calendar plugin <= 1.4.9 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Fri, 06 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar allows Cross Site Request Forgery. This issue affects Quick Event Calendar: from n/a through 1.4.9.
Title WordPress Quick Event Calendar <= 1.4.9 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:49.232Z

Reserved: 2025-02-21T16:46:11.506Z

Link: CVE-2025-27360

cve-icon Vulnrichment

Updated: 2025-06-06T14:52:10.301Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T13:15:27.593

Modified: 2026-06-17T09:03:27.673

Link: CVE-2025-27360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T08:30:26Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)