Simple calendar for Elementor
Simple calendar for Elementor has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 4.6, and the most serious one scores 5.3 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (67%). Other recurring categories include Missing Authorization.
Every one of the 3 issues recorded for Simple calendar for Elementor has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by haudayroi. Simple calendar for Elementor is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-1310Simple calendar for Elementor <= 1.6.6 - Missing Authorization to Unauthenticated Arbitrary Calendar Entry Deletion
Read the full analysisVulnerability Records

Simple calendar for Elementor
Author
Michael
Simple calendar plugin for Elementor to show e.g. availability on different days. You can choose between different layouts, colors, create multiple calendars and create custom status elements (names + CSS classes).
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C