Impact
The My Calendar – Accessible Event Manager plugin contains_auth parameter. Unvalidated user input is concatenated directly into SQL statements, allowing an attacker to inject additional queries. The primary impact is that an unauthenticated adversary can extract sensitive information such as user passwords, email addresses, event details, or other personal data stored by the plugin.
Affected Systems
All WordPress installations running My Calendar – Accessible Event Manager version 3.7.8 or earlier. The issue exists in every release up to and including 3.7.8 and is therefore applicable to every site that has the plugin installed within that version range.
Risk and Exploitability
The CVSS score of 7.5 classifies the flaw as high severity. Exploitation is considered time‑based blind, meaning it requires monitoring response times to infer successful injections, which increases effort and reduces the immediacy of attacks. The EPSS score of less than 1% suggests a very low probability of exploitation based on historical data. The vulnerability is not listed in CISA's KEV through unauthenticated HTTP requests to plugin endpoints that accept the mc_auth parameter, typical of a web application exploitation scenario.
OpenCVE Enrichment