CVE-2023-6360: Joedolson My Calendar

Critical severity, CVSS 9.8. EPSS: 63.1% chance of exploitation in the next 30 days.

The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.

Affected products

  • Joedolson My Calendar: before 3.4.22 (fixed in 3.4.22)

Published 2023-11-30. Last modified 2026-06-17.