← back to popular plugins
wordfence / plugin · google-calendar-events

Simple Calendar – Google Calendar Plugin

google-calendar-events
total installs
50,000
total vulns
1
critical
0
high
0
medium
1
low
0
latest vuln
patched
1
unpatched
0
avg time to patch
vulnerabilities (1)
Google Calendar Events <= 3.5.9 - Unauthenticated Insecure Direct Object Reference
medium ✓ patched
cvss score 5.3
cwe CWE-639: Authorization Bypass Through User-Controlled Key
published Dec 18, 2025
The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.5.9 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.