cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-fullcalendar wp-fullcalendar

Direction: descending
Feb 28, 2026

WP FullCalendar # CVE-2026-22351

CVE, Research URL

CVE-2026-22351

Application

WP FullCalendar

Date
Feb 20, 2026
Research Description
Missing Authorization vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP FullCalendar: from n/a through <= 1.6.
Affected versions
max 1.6.
Status
vulnerable
Jan 28, 2026

WP FullCalendar # CVE-2026-24523

CVE, Research URL

CVE-2026-24523

Application

WP FullCalendar

Date
Jan 23, 2026
Research Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Retrieve Embedded Sensitive Data.This issue affects WP FullCalendar: from n/a through <= 1.6.
Affected versions
max 1.6.
Status
vulnerable
Jan 08, 2025

WP FullCalendar # CVE-2025-22261

CVE, Research URL

CVE-2025-22261

Application

WP FullCalendar

Date
Jan 07, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite WP FullCalendar allows Stored XSS.This issue affects WP FullCalendar: from n/a through 1.5.
Affected versions
max 1.5.
Status
vulnerable
Jun 07, 2024

WP FullCalendar # CVE-2022-3891

CVE, Research URL

CVE-2022-3891

Application

WP FullCalendar

Date
Feb 13, 2023
Research Description
The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.
Affected versions
max 1.5.
Status
vulnerable