My Calendar <= 3.7.9 - Authenticated (Custom+) Missing Authorization to Unauthorized Event Publication via 'event_approved' Parameter
My Calendar – Accessible Event Manager
Minimum safe version
3.7.10
Update to 3.7.10 or later to address 30 fixable vulnerabilities
CVE-2026-40308
My Calendar – Accessible Event Manager <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
My Calendar <= 3.6.16 - Missing Authorization
CVE-2024-1274
CVE-2024-25916
My Calendar <= 3.4.23 - Authenticated (Admin+) Stored Cross-Site Scripting via Events
My Calendar <= 3.4.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
CVE-2023-6360
My Calendar <= 2.3.28 - Cross-Site Scripting (XSS)
My Calendar <= 2.3.29 - Arbitrary File Override & Reflected XSS
My Calendar <= 2.5.16 - Authenticated Cross-Site Scripting (XSS)
CVE-2023-23813
My Calendar <= 3.4.3 - Cross-Site Request Forgery
CVE-2022-47427
My Calendar <= 3.3.24.1 - Cross-Site Request Forgery
My Calendar < 2.3.10 - Reflected Cross-Site Scripting
My Calendar <= 2.3.29 - Path Traversal to Remote Code Execution
My Calendar < 2.3.30 - Reflected Cross-Site Scripting
My Calendar <= 2.5.16 - Authenticated Stored Cross-Site Scripting
My Calendar <= 3.3.16 - Administrator+ Stored Cross-Site Scripting
WordPress My Calendar plugin <= 3.3.16 - Unauthenticated Open Redirect vulnerability
WordPress My Calendar Plugin <= 2.3.28 - Cross Site Scripting
WordPress My Calendar Plugin <= 2.3.29 - Multiple Vulnerabilities
WordPress My Calendar Plugin 2.4.10 - Multiple Vulnerabilities
WordPress My Calendar plugin <=2.5.16 - Authenticated Cross-Site Scripting (XSS) vulnerability
WordPress My Calendar plugin <= 3.1.9 - Unauthenticated Cross-Site Scripting (XSS) vulnerability
CVE-2012-6527
CVE-2019-15713
CVE-2021-24927