PLUGIN SECURITY
Is My Calendar safe?
Accessible WordPress event calendar plugin. Manage single or recurring events, event venues, and display your calendar anywhere on your site.
What this plugin does
- Slug:
my-calendar - Author: Joe Dolson
- 20000+ active installs
- 94/100 rating (159 reviews on wordpress.org)
- 3149115 all-time downloads
- On WordPress.org since 2010-04-05
accessibilityevent calendarevent managerlocationvenue
Maintenance status
- Latest known version: 3.7.17
- Last updated: 2026-08-25 4:51pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
15 known CVEs on file for My Calendar.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-6854 | My Calendar – Accessible Event Manager [my-calendar] < 3.7.9 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | High 7.5 | < 3.7.9 | 3.7.9 | 2026-07-07 | ✓ fixed in latest |
| CVE-2026-11896 | My Calendar – Accessible Event Manager [my-calendar] < 3.7.15 | Authorization Bypass Through User-Controlled Key | Medium 5.3 | < 3.7.15 | 3.7.15 | 2026-07-01 | ✓ fixed in latest |
| CVE-2026-7525 | My Calendar – Accessible Event Manager [my-calendar] < 3.7.10 | Missing Authorization | Medium 4.3 | < 3.7.10 | 3.7.10 | 2026-05-13 | ✓ fixed in latest |
| CVE-2026-40308 | My Calendar – Accessible Event Manager [my-calendar] < 3.7.7 | Authorization Bypass Through User-Controlled Key | Unknown | < 3.7.7 | 3.7.7 | 2026-04-16 | ✓ fixed in latest |
| CVE-2025-67592 | My Calendar – Accessible Event Manager [my-calendar] < 3.6.17 | Missing Authorization | Medium 4.3 | < 3.6.17 | 3.6.17 | 2025-12-09 | ✓ fixed in latest |
| CVE-2024-25916 | My Calendar – Accessible Event Manager [my-calendar] < 3.4.24 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 3.4.24 | 3.4.24 | 2024-02-11 | ✓ fixed in latest |
| CVE-2024-1274 | My Calendar – Accessible Event Manager [my-calendar] < 3.4.24 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.4.24 | 3.4.24 | 2024-02-11 | ✓ fixed in latest |
| CVE-2023-6360 | My Calendar – Accessible Event Manager [my-calendar] < 3.4.22 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | Critical 9.8 | < 3.4.22 | 3.4.22 | 2023-11-26 | ✓ fixed in latest |
+ 28 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-23813 | My Calendar – Accessible Event Manager [my-calendar] < 3.4.4 | Cross-Site Request Forgery (CSRF) | Medium 5.4 | < 3.4.4 | 3.4.4 | 2023-01-20 | ✓ fixed in latest |
| CVE-2022-47427 | My Calendar – Accessible Event Manager [my-calendar] < 3.3.25 | Cross-Site Request Forgery (CSRF) | Medium 5.4 | < 3.3.25 | 3.3.25 | 2023-01-03 | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 3.3.17 | — | Unknown | < 3.3.17 | 3.3.17 | 2022-07-18 | ✓ fixed in latest |
| CVE-2021-24927 | My Calendar – Accessible Event Manager [my-calendar] < 3.2.18 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 3.2.18 | 3.2.18 | 2021-11-01 | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 3.1.10 | — | Unknown | < 3.1.10 | 3.1.10 | 2019-05-06 | ✓ fixed in latest |
| CVE-2019-15713 | My Calendar – Accessible Event Manager [my-calendar] < 3.1.10 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 3.1.10 | 3.1.10 | 2019-04-30 | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 2.5.17 | — | Unknown | < 2.5.17 | 2.5.17 | 2018-04-05 | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 2.5.17 | — | Unknown | < 2.5.17 | 2.5.17 | 2018-04-04 | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 2.4.11 | — | Unknown | < 2.4.11 | 2.4.11 | 2015-11-06 | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 2.3.30 | — | Unknown | < 2.3.30 | 2.3.30 | 2015-05-15 | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 2.3.30 | — | Unknown | < 2.3.30 | 2.3.30 | 2015-05-15 | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 2.3.30 | — | Unknown | < 2.3.30 | 2.3.30 | 2015-05-15 | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 2.3.29 | — | Unknown | < 2.3.29 | 2.3.29 | 2015-04-20 | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 2.3.10 | — | Unknown | < 2.3.10 | 2.3.10 | 2015-04-20 | ✓ fixed in latest |
| CVE-2012-6527 | My Calendar – Accessible Event Manager [my-calendar] < 1.10.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Unknown | < 1.10.5 | 1.10.5 | 2012-01-18 | ✓ fixed in latest |
| CVE-2022-36371 | My Calendar – Accessible Event Manager [my-calendar] < 3.3.17 | — | Unknown | < 3.3.17 | 3.3.17 | 0000-00-00 | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 3.7.4 | — | Unknown | < 3.7.4 | 3.7.4 | 0000-00-00 | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 2.5.17 | — | Unknown | < 2.5.17 | 2.5.17 | — | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 2.3.30 | — | Unknown | < 2.3.30 | 2.3.30 | — | ✓ fixed in latest |
| — | My Calendar – Accessible Event Manager [my-calendar] < 2.3.29 | — | Unknown | < 2.3.29 | 2.3.29 | — | ✓ fixed in latest |
| — | My Calendar <= 2.3.28 - Cross-Site Scripting (XSS) | — | Unknown | < 2.3.29 | 2.3.29 | — | ✓ fixed in latest |
| — | My Calendar <= 2.3.29 - Arbitrary File Override & Reflected XSS | — | Unknown | < 2.3.30 | 2.3.30 | — | ✓ fixed in latest |
| — | My Calendar <= 2.5.16 - Authenticated Cross-Site Scripting (XSS) | — | Unknown | < 2.5.17 | 2.5.17 | — | ✓ fixed in latest |
| CVE-2022-47427 | My Calendar < 3.3.25 - Event/Location Deletion via CSRF | — | Unknown | < 3.3.25 | 3.3.25 | — | ✓ fixed in latest |
| CVE-2023-23813 | My Calendar < 3.4.4 - Cross-Site Request Forgery | — | Unknown | < 3.4.4 | 3.4.4 | — | ✓ fixed in latest |
| CVE-2024-25916 | My Calendar < 3.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | — | Unknown | < 3.4.24 | 3.4.24 | — | ✓ fixed in latest |
| CVE-2024-1274 | My Calendar < 3.4.24 - Authenticated Stored XSS | — | Unknown | < 3.4.24 | 3.4.24 | — | ✓ fixed in latest |
| CVE-2026-2355 | My Calendar – Accessible Event Manager < 3.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | — | Unknown | < 3.7.4 | 3.7.4 | — | ✓ fixed in latest |
How to fix it
Keep My Calendar updated — 3.7.17 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget — 500000+ active installs — 58/100 (162) — max PHP 8.4
- Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) — 100000+ active installs — 96/100 (93) — max PHP 8.4
- Accessibility by UserWay — 80000+ active installs — 80/100 (57) — max PHP 8.4
- WP Accessibility — 60000+ active installs — 96/100 (68) — max PHP 8.4
- Alt Text AI – Automatically generate image alt text for SEO and accessibility — 20000+ active installs — 94/100 (35)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.