Event Calendar WordPress Plugin Unauthenticated Arbitrary Calendar Deletion Vulnerability

Vulnerability

A vulnerability exists in the Event Calendar WordPress plugin in versions through 1.0.4, where the plugin fails to properly authorize delete actions. This flaw allows unauthenticated users to delete any calendar at will.

Impact

Exploitation of this vulnerability allows for the unauthorized deletion of calendars, potentially leading to data loss.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.