Description
Missing Authorization vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP FullCalendar: from n/a through <= 1.6.
Published: 2026-02-20
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized privileged access
Action: Patch
AI Analysis

Impact

Missing Authorization vulnerability in Marcus' WP FullCalendar plugin allows exploitation of incorrectly configured access control. The plugin does not enforce proper authorization for certain operations, enabling an attacker to perform privileged actions such as creating, modifying, or deleting calendar events, or viewing sensitive event data. This flaw is classified as CWE-862 and can compromise the confidentiality, integrity, and availability of the site's scheduling information.

Affected Systems

Version 1.6 and earlier of Marcus' WP FullCalendar WordPress plugin are affected. The vulnerability applies to all WordPress sites that have this plugin installed and activated, regardless of the website's configuration or host.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity vulnerability. The EPSS score is less than 1%, suggesting a low probability of real-world exploitation at this time, and the flaw is not listed in the CISA KEV catalog. Based on the plugin's nature as a WordPress extension, the likely attack vector is remote HTTP requests to the plugin's endpoints. An attacker with any user access to the site, or who can send crafted requests, could exploit this weakness without needing additional privileges, making it a significant risk in environments lacking stricter access controls.

Generated by OpenCVE AI on April 28, 2026 at 17:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP FullCalendar plugin to version 1.7 or later to apply the vendor‑supplied fix.
  • Restrict public access to the plugin's administrative URLs, using .htaccess rules or a security plugin, to reduce exposure.
  • Review and enforce the plugin's access control settings, ensuring that only users with administrator privileges can perform event modification or creation.

Generated by OpenCVE AI on April 28, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 23 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Marcus (aka @msykes)
Marcus (aka @msykes) wp Fullcalendar
Wordpress
Wordpress wordpress
Vendors & Products Marcus (aka @msykes)
Marcus (aka @msykes) wp Fullcalendar
Wordpress
Wordpress wordpress

Fri, 20 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP FullCalendar: from n/a through <= 1.6.
Title WordPress WP FullCalendar plugin <= 1.6 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Marcus (aka @msykes) Wp Fullcalendar
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:47:54.145Z

Reserved: 2026-01-07T12:21:19.920Z

Link: CVE-2026-22351

cve-icon Vulnrichment

Updated: 2026-02-23T20:56:55.476Z

cve-icon NVD

Status : Deferred

Published: 2026-02-20T16:22:34.237

Modified: 2026-04-28T19:36:30.863

Link: CVE-2026-22351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T17:45:16Z

Weaknesses