Impact
A missing authorization check within the My Calendar plugin for WordPress allows an attacker to access restricted functionality. The weakness is classified as CWE‑862 (Missing Authorization). The result is that users without the proper privileges could potentially view or modify calendar data and settings, undermining confidentiality, integrity, and availability of the calendar feature.
Affected Systems
The plugin is distributed by Joe Dolson under the name My Calendar. All releases from the earliest version through version 3.6.16 are affected. Any WordPress installation that includes My Calendar 3.6.16 or older is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score of less than 1 % shows a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web interface of a WordPress site that hosts the vulnerable plugin; an attacker can send crafted requests to the plugin’s endpoints without authentication, thereby bypassing normal access controls.
OpenCVE Enrichment