Description
Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spiffy Calendar: from n/a through <= 5.0.7.
Published: 2025-12-24
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Broken Access Control
Action: Apply Patch
AI Analysis

Impact

The reported vulnerability is a missing authorization flaw in the Spiffy Calendar plugin for WordPress. This break in access control allows an attacker to invoke plugin functions or view data that should be restricted to privileged users. The weakness is a classic instance of CWE‑862 Unauthorized Access, potentially leading to data exposure or unauthorized modification of calendar events.

Affected Systems

Affected systems are WordPress sites that have the Spiffy Calendar plugin installed in versions up to and including 5.0.7. The plugin, developed by Spiffy Plugins, is distributed as a WordPress plugin. No other versions are flagged as vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates a low‑to‑moderate severity. The EPSS score of less than 1% suggests exploitation is unlikely in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly documented, but the missing checks imply that any user who can reach the plugin's endpoints could potentially trigger the flaw; therefore, the risk is most acute in environments where non‑privileged users can access these endpoints.

Generated by OpenCVE AI on April 28, 2026 at 18:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Spiffy Calendar to the latest available version (at least 5.0.8) to apply the authorization fix.
  • If an upgrade cannot be performed immediately, restrict frontend access to the plugin’s features by applying WordPress role‑based access controls or disabling the plugin on public sites.
  • Review and audit user accounts that have access to the plugin’s settings to confirm that only authorized personnel can modify or view calendar data.

Generated by OpenCVE AI on April 28, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 29 Dec 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Spiffyplugins
Spiffyplugins spiffy Calendar
Wordpress
Wordpress wordpress
Vendors & Products Spiffyplugins
Spiffyplugins spiffy Calendar
Wordpress
Wordpress wordpress

Wed, 24 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spiffy Calendar: from n/a through <= 5.0.7.
Title WordPress Spiffy Calendar plugin <= 5.0.7 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Spiffyplugins Spiffy Calendar
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:29.274Z

Reserved: 2025-12-19T10:16:57.339Z

Link: CVE-2025-68523

cve-icon Vulnrichment

Updated: 2025-12-24T19:09:08.070Z

cve-icon NVD

Status : Deferred

Published: 2025-12-24T13:16:21.877

Modified: 2026-04-27T19:16:27.897

Link: CVE-2025-68523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T18:30:37Z

Weaknesses