Impact
The reported vulnerability is a missing authorization flaw in the Spiffy Calendar plugin for WordPress. This break in access control allows an attacker to invoke plugin functions or view data that should be restricted to privileged users. The weakness is a classic instance of CWE‑862 Unauthorized Access, potentially leading to data exposure or unauthorized modification of calendar events.
Affected Systems
Affected systems are WordPress sites that have the Spiffy Calendar plugin installed in versions up to and including 5.0.7. The plugin, developed by Spiffy Plugins, is distributed as a WordPress plugin. No other versions are flagged as vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑moderate severity. The EPSS score of less than 1% suggests exploitation is unlikely in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly documented, but the missing checks imply that any user who can reach the plugin's endpoints could potentially trigger the flaw; therefore, the risk is most acute in environments where non‑privileged users can access these endpoints.
OpenCVE Enrichment