CVE Database /
CVE-2026-11896
CVE · Medium
CVE-2026-11896 — My Calendar – Accessible Event Manager [my-calendar] < 3.7.15
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-11896
|
My Calendar – Accessible Event Manager [my-calendar] < 3.7.15 |
Authorization Bypass Through User-Controlled Key |
Medium
5.3
|
< 3.7.15
|
3.7.15 |
2026-07-01 |
—
|
CVE-2026-11896
The My Calendar plugin for WordPress contains a flaw in its handling of user-submitted data that can be exploited by attackers to access unauthorized information. Specifically, the 'vcal' parameter is not properly validated, allowing unauthenticated users to obtain sensitive event details such as titles, descriptions, dates, and locations from non-public events. This vulnerability affects all versions up to 3.7.14.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings