CVE · Medium

CVE-2026-7525 — My Calendar – Accessible Event Manager [my-calendar] < 3.7.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-7525 My Calendar – Accessible Event Manager [my-calendar] < 3.7.10 Missing Authorization Medium 4.3 < 3.7.10 3.7.10 2026-05-13

CVE-2026-7525

The My Calendar plugin for WordPress has an authorization flaw that affects all versions up to 3.7.9. Users with custom-level access and above can exploit this vulnerability by altering the data sent in a form submission, allowing them to publish events or change their status without proper clearance. This issue arises from the fact that the plugin's access controls are enforced only on the client-side, making it easy for attackers to bypass these restrictions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.