Ajax Archive Calendar

Ajax Archive Calendar has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Ajax Archive Calendar has a vendor fix available, so running the current release closes it.

All of these findings were reported by Ngô Thiên An (ancorn_). Ajax Archive Calendar is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Ajax Archive Calendar vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2023-46069

Ajax Archive Calendar <= 2.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Read the full analysis

Vulnerability Records

1 records
Ajax Archive Calendar banner
Latestv3.0.0

Ajax Archive Calendar

osman sorkar

Author

osman sorkar

4.5(4)
90/100
Last Updated
2025-07-28 (1y ago)
Active Installs
1,000+
Downloads
21,463
Requires WP
3.0+
Requires PHP
0+
Tested up to
WP 6.8.8
Created
2014-02-12 (13y ago)

The Ajax Archive Calendar plugin goes beyond a standard calendar, offering a powerful archive solution for your WordPress site. It’s built upon and customizes the default WordPress calendar, providing a familiar yet enhanced experience. We’re confident you’ll appreciate its features, available in both Bengali and English. Now it is support WPML. f you need any modifications or encounter any problems, please report them on our GitHub repository. https://github.com/osmansorkar/ajax-archive-calendar

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C