Description
Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor simple-calendar-for-elementor allows Cross Site Request Forgery.This issue affects Simple calendar for Elementor: from n/a through <= 1.6.5.
Published: 2025-05-07
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Simple calendar for Elementor plugin contains a flaw that allows an attacker to force a logged‑in administrator to perform actions on the site without the administrator’s explicit consent. This occurs because the plugin fails to validate that requests originate from a legitimate source, allowing exploitation when an administrator visits a crafted URL or malicious content. The resulting impact is a compromise of the integrity of calendar data and potentially other privileged actions within WordPress that the authenticated user can perform. The weakness is a classic CSRF type flaw identified as CWE-352.

Affected Systems

All installations of the Simple calendar for Elementor plugin on WordPress that are running version 1.6.5 or earlier are affected. No other WordPress core components or plugins are listed as vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low current probability of exploitation. The vulnerability is not cataloged in CISA’s KEV database. The most likely attack vector involves an attacker tricking an authenticated administrator into visiting a maliciously crafted link or embedding the URL in an email or webpage. No publicly available exploit code has been confirmed, but the ease of CSRF attacks means the risk is real for sites where administrators are not vigilant against malicious links.

Generated by OpenCVE AI on May 1, 2026 at 08:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Simple calendar for Elementor plugin to the latest available version that includes the CSRF fix.
  • If an immediate update is not feasible, disable or delete the plugin to prevent the vulnerability from being usable.
  • Add or strengthen general WordPress security controls such as enforcing nonces on all admin requests, using a security plugin that blocks unsolicited POSTs, and monitoring logs for unexpected requests to plugin endpoints.

Generated by OpenCVE AI on May 1, 2026 at 08:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13794 Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor allows Cross Site Request Forgery. This issue affects Simple calendar for Elementor: from n/a through 1.6.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor allows Cross Site Request Forgery. This issue affects Simple calendar for Elementor: from n/a through 1.6.5. Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor simple-calendar-for-elementor allows Cross Site Request Forgery.This issue affects Simple calendar for Elementor: from n/a through <= 1.6.5.
Title WordPress Simple calendar for Elementor <= 1.6.5 - Cross Site Request Forgery (CSRF) Vulnerability WordPress Simple calendar for Elementor plugin <= 1.6.5 - Cross Site Request Forgery (CSRF) Vulnerability
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00017}

epss

{'score': 0.0002}


Mon, 09 Jun 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Migaweb
Migaweb simple Calendar For Elementor
CPEs cpe:2.3:a:migaweb:simple_calendar_for_elementor:*:*:*:*:*:wordpress:*:*
Vendors & Products Migaweb
Migaweb simple Calendar For Elementor

Wed, 07 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor allows Cross Site Request Forgery. This issue affects Simple calendar for Elementor: from n/a through 1.6.5.
Title WordPress Simple calendar for Elementor <= 1.6.5 - Cross Site Request Forgery (CSRF) Vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Migaweb Simple Calendar For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:44.478Z

Reserved: 2025-05-07T09:39:53.906Z

Link: CVE-2025-47542

cve-icon Vulnrichment

Updated: 2025-05-07T17:20:30.232Z

cve-icon NVD

Status : Modified

Published: 2025-05-07T15:16:10.850

Modified: 2026-04-23T15:30:27.133

Link: CVE-2025-47542

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T09:00:12Z

Weaknesses