CVE · Medium

CVE-2026-11896 — My Calendar – Accessible Event Manager [my-calendar] < 3.7.15

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-11896 My Calendar – Accessible Event Manager [my-calendar] < 3.7.15 Authorization Bypass Through User-Controlled Key Medium 5.3 < 3.7.15 3.7.15 2026-07-01

CVE-2026-11896

The My Calendar plugin for WordPress contains a flaw in its handling of user-submitted data that can be exploited by attackers to access unauthorized information. Specifically, the 'vcal' parameter is not properly validated, allowing unauthenticated users to obtain sensitive event details such as titles, descriptions, dates, and locations from non-public events. This vulnerability affects all versions up to 3.7.14.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.