CVE · High

CVE-2026-6854 — My Calendar – Accessible Event Manager [my-calendar] < 3.7.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6854 My Calendar – Accessible Event Manager [my-calendar] < 3.7.9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 3.7.9 3.7.9 2026-07-07

CVE-2026-6854

The My Calendar plugin for WordPress contains a security flaw in versions 3.7.8 and earlier, allowing malicious input to inject unauthorized SQL code through the 'mc_auth' parameter. This vulnerability enables attackers to craft additional SQL queries that can potentially reveal confidential data stored within the database without requiring authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.