Vulnerabilities and security researches forwp-fullcalendar wp-fullcalendar
Direction: descendingFeb 28, 2026
WP FullCalendar # CVE-2026-22351
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 20, 2026
- Research Description
- Missing Authorization vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP FullCalendar: from n/a through <= 1.6.
- Affected versions
-
max 1.6.
- Status
-
vulnerable
Jan 28, 2026
WP FullCalendar # CVE-2026-24523
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 23, 2026
- Research Description
- Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Retrieve Embedded Sensitive Data.This issue affects WP FullCalendar: from n/a through <= 1.6.
- Affected versions
-
max 1.6.
- Status
-
vulnerable
Jan 08, 2025
WP FullCalendar # CVE-2025-22261
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 07, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite WP FullCalendar allows Stored XSS.This issue affects WP FullCalendar: from n/a through 1.5.
- Affected versions
-
max 1.5.
- Status
-
vulnerable
Jun 07, 2024
WP FullCalendar # CVE-2022-3891
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 13, 2023
- Research Description
- The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.
- Affected versions
-
max 1.5.
- Status
-
vulnerable