Simple calendar for Elementor

Simple calendar for Elementor has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 4.6, and the most serious one scores 5.3 out of 10. 2025 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (67%). Other recurring categories include Missing Authorization.

Every one of the 3 issues recorded for Simple calendar for Elementor has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, most of them (2) reported by haudayroi. Simple calendar for Elementor is installed on roughly 600 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
4.6/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Simple calendar for Elementor vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2026-1310

Simple calendar for Elementor <= 1.6.6 - Missing Authorization to Unauthenticated Arbitrary Calendar Entry Deletion

Read the full analysis

Vulnerability Records

3 records
Simple calendar for Elementor banner
Latestv1.6.7

Simple calendar for Elementor

Michael

Author

Michael

5.0(3)
100/100
Last Updated
2026-01-22 (8mo ago)
Active Installs
600+
Downloads
8,077
Requires WP
5.2+
Requires PHP
7.2+
Tested up to
WP 6.9.7
Created
2022-09-14 (4y ago)

Simple calendar plugin for Elementor to show e.g. availability on different days. You can choose between different layouts, colors, create multiple calendars and create custom status elements (names + CSS classes).

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C