PLUGIN SECURITY

Is My Calendar safe?

Accessible WordPress event calendar plugin. Manage single or recurring events, event venues, and display your calendar anywhere on your site.

What this plugin does

  • Slug: my-calendar
  • Author: Joe Dolson
  • 20000+ active installs
  • 94/100 rating (159 reviews on wordpress.org)
  • 3149115 all-time downloads
  • On WordPress.org since 2010-04-05

accessibilityevent calendarevent managerlocationvenue

Maintenance status

  • Latest known version: 3.7.17
  • Last updated: 2026-08-25 4:51pm GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

15 known CVEs on file for My Calendar.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-6854 My Calendar – Accessible Event Manager [my-calendar] < 3.7.9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 3.7.9 3.7.9 2026-07-07 ✓ fixed in latest
CVE-2026-11896 My Calendar – Accessible Event Manager [my-calendar] < 3.7.15 Authorization Bypass Through User-Controlled Key Medium 5.3 < 3.7.15 3.7.15 2026-07-01 ✓ fixed in latest
CVE-2026-7525 My Calendar – Accessible Event Manager [my-calendar] < 3.7.10 Missing Authorization Medium 4.3 < 3.7.10 3.7.10 2026-05-13 ✓ fixed in latest
CVE-2026-40308 My Calendar – Accessible Event Manager [my-calendar] < 3.7.7 Authorization Bypass Through User-Controlled Key Unknown < 3.7.7 3.7.7 2026-04-16 ✓ fixed in latest
CVE-2025-67592 My Calendar – Accessible Event Manager [my-calendar] < 3.6.17 Missing Authorization Medium 4.3 < 3.6.17 3.6.17 2025-12-09 ✓ fixed in latest
CVE-2024-25916 My Calendar – Accessible Event Manager [my-calendar] < 3.4.24 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 3.4.24 3.4.24 2024-02-11 ✓ fixed in latest
CVE-2024-1274 My Calendar – Accessible Event Manager [my-calendar] < 3.4.24 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.4.24 3.4.24 2024-02-11 ✓ fixed in latest
CVE-2023-6360 My Calendar – Accessible Event Manager [my-calendar] < 3.4.22 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 3.4.22 3.4.22 2023-11-26 ✓ fixed in latest
+ 28 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-23813 My Calendar – Accessible Event Manager [my-calendar] < 3.4.4 Cross-Site Request Forgery (CSRF) Medium 5.4 < 3.4.4 3.4.4 2023-01-20 ✓ fixed in latest
CVE-2022-47427 My Calendar – Accessible Event Manager [my-calendar] < 3.3.25 Cross-Site Request Forgery (CSRF) Medium 5.4 < 3.3.25 3.3.25 2023-01-03 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 3.3.17 Unknown < 3.3.17 3.3.17 2022-07-18 ✓ fixed in latest
CVE-2021-24927 My Calendar – Accessible Event Manager [my-calendar] < 3.2.18 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 3.2.18 3.2.18 2021-11-01 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 3.1.10 Unknown < 3.1.10 3.1.10 2019-05-06 ✓ fixed in latest
CVE-2019-15713 My Calendar – Accessible Event Manager [my-calendar] < 3.1.10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.10 3.1.10 2019-04-30 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 2.5.17 Unknown < 2.5.17 2.5.17 2018-04-05 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 2.5.17 Unknown < 2.5.17 2.5.17 2018-04-04 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 2.4.11 Unknown < 2.4.11 2.4.11 2015-11-06 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 2.3.30 Unknown < 2.3.30 2.3.30 2015-05-15 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 2.3.30 Unknown < 2.3.30 2.3.30 2015-05-15 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 2.3.30 Unknown < 2.3.30 2.3.30 2015-05-15 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 2.3.29 Unknown < 2.3.29 2.3.29 2015-04-20 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 2.3.10 Unknown < 2.3.10 2.3.10 2015-04-20 ✓ fixed in latest
CVE-2012-6527 My Calendar – Accessible Event Manager [my-calendar] < 1.10.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 1.10.5 1.10.5 2012-01-18 ✓ fixed in latest
CVE-2022-36371 My Calendar – Accessible Event Manager [my-calendar] < 3.3.17 Unknown < 3.3.17 3.3.17 0000-00-00 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 3.7.4 Unknown < 3.7.4 3.7.4 0000-00-00 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 2.5.17 Unknown < 2.5.17 2.5.17 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 2.3.30 Unknown < 2.3.30 2.3.30 ✓ fixed in latest
My Calendar – Accessible Event Manager [my-calendar] < 2.3.29 Unknown < 2.3.29 2.3.29 ✓ fixed in latest
My Calendar <= 2.3.28 - Cross-Site Scripting (XSS) Unknown < 2.3.29 2.3.29 ✓ fixed in latest
My Calendar <= 2.3.29 - Arbitrary File Override & Reflected XSS Unknown < 2.3.30 2.3.30 ✓ fixed in latest
My Calendar <= 2.5.16 - Authenticated Cross-Site Scripting (XSS) Unknown < 2.5.17 2.5.17 ✓ fixed in latest
CVE-2022-47427 My Calendar < 3.3.25 - Event/Location Deletion via CSRF Unknown < 3.3.25 3.3.25 ✓ fixed in latest
CVE-2023-23813 My Calendar < 3.4.4 - Cross-Site Request Forgery Unknown < 3.4.4 3.4.4 ✓ fixed in latest
CVE-2024-25916 My Calendar < 3.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Unknown < 3.4.24 3.4.24 ✓ fixed in latest
CVE-2024-1274 My Calendar < 3.4.24 - Authenticated Stored XSS Unknown < 3.4.24 3.4.24 ✓ fixed in latest
CVE-2026-2355 My Calendar – Accessible Event Manager < 3.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes Unknown < 3.7.4 3.7.4 ✓ fixed in latest

How to fix it

Keep My Calendar updated — 3.7.17 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.