CVE-2023-6360: Joedolson My Calendar
Critical severity, CVSS 9.8. EPSS: 63.1% chance of exploitation in the next 30 days.
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.
Affected products
- Joedolson My Calendar: before 3.4.22 (fixed in 3.4.22)
Published 2023-11-30. Last modified 2026-06-17.