Skip to content

Known CVE

WordPress My Calendar <3.4.22 - SQL Injection

WordPress My Calendar plugin versions before 3.4.22 are vulnerable to an unauthenticated SQL injection within the 'from' and 'to' parameters of the '/my-calendar/v1/events' REST route.

CVE-2023-6360

Critical2023CVSS 9.8CWE-89

cve2023 · sqli · wp · wordpress · wpscan · wp-plugin · my-calendar · joedolson

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website