My Calendar – Accessible Event Manager

My Calendar – Accessible Event Manager has 22 disclosed vulnerabilities in the WordSec catalog, reported between 2012 and 2026; all 22 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 3 high. 2026 was the busiest year with 7 disclosures.

The most common weakness is Cross-Site Scripting, behind 12 of the records (55%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Cross-Site Request Forgery (CSRF).

Every one of the 22 issues recorded for My Calendar – Accessible Event Manager has a vendor fix available, so running the current release closes all known holes.

18 independent researchers contributed these findings, most of them (2) reported by Wordfence PRISM. My Calendar – Accessible Event Manager is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891005.04.2010Today18.01.20126.1My Calendar < 1.10.5 - Cross-Site Scripting CVSS 6.1 · 18.01.201220.04.20156.1My Calendar < 2.3.10 - Reflected Cross-Site Scripting CVSS 6.1 · 20.04.201515.05.20156.1My Calendar < 2.3.30 - Reflected Cross-Site Scripting CVSS 6.1 · 15.05.20159.8My Calendar <= 2.3.29 - Path Traversal to Remote Code Execution CVSS 9.8 · 15.05.201504.04.20186.4My Calendar <= 2.5.16 - Authenticated Stored Cross-Site Scripting CVSS 6.4 · 04.04.201830.04.20196.1My Calendar <= 3.1.9 - Unauthenticated Cross-Site Scripting CVSS 6.1 · 30.04.201901.11.20215.4My Calendar <= 3.2.17 - Subscriber+ Reflected Cross-Site Scripting CVSS 5.4 · 01.11.202118.07.20225.5My Calendar <= 3.3.16 - Administrator+ Stored Cross-Site Scripting CVSS 5.5 · 18.07.202202.08.20224.7My Calendar <= 3.3.16 - Open Redirect CVSS 4.7 · 02.08.202203.01.20237.1My Calendar <= 3.3.24.1 - Cross-Site Request Forgery CVSS 7.1 · 03.01.202320.01.20238.8My Calendar <= 3.4.3 - Cross-Site Request Forgery CVSS 8.8 · 20.01.202326.11.20239.8My Calendar <= 3.4.21 - Unauthenticated SQL Injection CVSS 9.8 · 26.11.202311.02.20244.4My Calendar <= 3.4.23 - Authenticated (Admin+) Stored Cross-Site Scripting via Events CVSS 4.4 · 11.02.20246.4My Calendar <= 3.4.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 11.02.202415.12.20254.3My Calendar <= 3.6.16 - Missing Authorization CVSS 4.3 · 15.12.202503.03.20266.4My Calendar – Accessible Event Manager <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes CVSS 6.4 · 03.03.202616.04.20265.3My Calendar < 3.7.7 - Unauthenticated Denial of Service CVSS 5.3 · 16.04.202613.05.20264.3My Calendar <= 3.7.9 - Authenticated (Custom+) Missing Authorization to Unauthorized Event Publication via 'event_approved' Parameter CVSS 4.3 · 13.05.202601.07.20265.3My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter CVSS 5.3 · 01.07.202607.07.20267.5My Calendar <= 3.7.8 - Unauthenticated SQL Injection via 'mc_auth' and 'mc_host' Parameters CVSS 7.5 · 07.07.202608.09.20266.4My Calendar <= 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes CVSS 6.4 · 08.09.20266.4My Calendar <= 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fallback' Shortcode Attribute CVSS 6.4 · 08.09.2026

Strategic Overview

Avg CVSSMedium
6.3/ 10
Patch Coverage100%
Open

0

Fixed

22

Get automatic notifications for all My Calendar – Accessible Event Manager vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2023-6360

My Calendar <= 3.4.21 - Unauthenticated SQL Injection

Read the full analysis

Vulnerability Records

22 records
2026-09-08 14:30CVE-2026-77186
6.4
Medium
Wordfence PRISMYes
2026-09-08 14:29CVE-2026-77187
6.4
Medium
Wordfence PRISMYes
2026-07-07 23:19CVE-2026-6854
7.5
High
Leonid Semenenko (lsemenenko)Yes
2026-07-01 20:04CVE-2026-11896
5.3
Medium
Athiwat Tiprasaharn (Jitlada)Yes
2026-05-13 00:00CVE-2026-7525
4.3
Medium
type5afeYes
2026-04-16 00:00CVE-2026-40308
5.3
Medium
minhi1Yes
2026-03-03 22:33CVE-2026-2355
6.4
Medium
Muhammad Yudha - DJYes
2025-12-15 00:00CVE-2025-67592
4.3
Medium
Doan Dinh Van (d52v)Yes
2024-02-11 00:00CVE-2024-1274
4.4
Medium
cyc707Yes
2024-02-11 00:00CVE-2024-25916
6.4
Medium
Steven JulianYes
Showing 1–10 of 22 reports
My Calendar – Accessible Event Manager banner
Latestv3.8.4

My Calendar – Accessible Event Manager

Joe Dolson

Author

Joe Dolson

4.7(159)
94/100
Last Updated
2026-09-04 (8d ago)
Active Installs
20,000+
Downloads
3,173,776
Requires WP
6.5+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2010-04-05 (17y ago)

My Calendar offers easy-to-use WordPress event management with rich options for custom displays. Display individual event calendars in WordPress Multisite, offer multiple views of calendars limited by event categories, locations or author, or show simple text-based lists of your upcoming events. Rich Event Calendar Features You’ll find enormous design flexibility for your custom calendar. With recurring event support, design customization tools, custom templating, and category and venue support out of the box, My Calendar gives you a great feature set to get your calendar set up. Built with Accessibility in Mind My Calendar is an events calendar focused on holistic accessibility: providing a positive experience for site visitors and administrators who use assistive technology. It includes built-in settings where you can describe the ADA compliance features of your events and venues. Accessibility is a critical part of your website, so your audience can get equal access and experience to the events you list. Learn about accessible events or visit the My Calendar demo Accessibility-first Software While My Calendar has a strong focus on backwards compatibility, it is officially built with an accessibility first mindset. That means that if a choice has to be made between improving accessibility and breaking backwards compatibility, the more accessible choice will always come first. Premium Event Management Looking for more? Buy My Calendar Pro, the premium extension for My Calendar. My Calendar Pro adds tons of great additional features: Support for user-submitted events, Custom field creation and management, integration between posting and event creation, Import events from outside sources, and support for sharing events between multiple sites. Sell Event Tickets Do you sell tickets for your events? Use My Tickets and sell tickets for My Calendar events. Set prices, ticket availability, and sell multiple events at the same time using My Tickets. Features: Calendar grid, card, and list views of events Month, multi-month, week, or daily view. Mini-calendar for compact displays (as widget or shortcode) Widgets: today’s events, upcoming events, mini calendar, event search Customize templates for event output Limit views by categories, location, author, or host Extensive support for recurring events. Edit or add single dates in recurring events Rich permissions handling to restrict access to parts of My Calendar Email notifications when events are scheduled or drafted Post to X, Bluesky, or Mastodon when events are created (using XPoster) Event location management Fetch events from a remote database. (Sharing events in a network of sites.) Multisite-friendly Integrated help page Shortcode Generator to create customized views of My Calendar SEO with JSON-LD structured data for events and venues. Export or subscribe via iCal or Google Calendar. Completely responsive events views Extensive public documentation. Hundreds of actions and filters for custom development Accessibility My Calendar is designed with accessibility in mind. All interfaces – both front and back end – are tested with various assistive technology. The plugin includes features for showing the accessibility services available for events and at physical venues, as well as providing access to your event information for users with disabilities. What’s in My Calendar Pro? Let your site visitors submit events to your site (pay to post or free!). Let logged-in users edit their events from the front-end. Custom field creator Create events when you publish a blog post Publish a blog post when you create an event Advanced search features Import events from .ics or .csv formats via file or URL. REST API support for sharing events between multiple sites. Translations Visit WordPress Translations to check progress or contribute to your language. Translating my plugins is always appreciated. Visit WordPress translations to help get your language to 100%!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C