Ajax Archive Calendar
Ajax Archive Calendar has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Ajax Archive Calendar has a vendor fix available, so running the current release closes it.
All of these findings were reported by Ngô Thiên An (ancorn_). Ajax Archive Calendar is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2023-46069Ajax Archive Calendar <= 2.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Read the full analysisVulnerability Records

Ajax Archive Calendar
Author
osman sorkar
The Ajax Archive Calendar plugin goes beyond a standard calendar, offering a powerful archive solution for your WordPress site. It’s built upon and customizes the default WordPress calendar, providing a familiar yet enhanced experience. We’re confident you’ll appreciate its features, available in both Bengali and English. Now it is support WPML. f you need any modifications or encounter any problems, please report them on our GitHub repository. https://github.com/osmansorkar/ajax-archive-calendar
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C