plugin

Google Calendar Events Vulnerabilities

15 known security issues reported for the Google Calendar Events WordPress plugin. Most recent disclosed Dec 30, 2025.

7 medium

Running Google Calendar Events on your site? Check whether your installed version is affected.

Scan your site free

Simple Calendar &#8211; Google Calendar Plugin [google-calendar-events] <= 3.5.9 (unfixed)

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in SimpleCalendar Google Calendar Events google-calendar-events allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Google Calendar Events: from n/a through <= 3.5.9.

Affected:
up to 3.5.9
Fix:
No patched version reported
Disclosed:
Dec 30, 2025

CVE-2025-68979 on NVD →

Google Calendar Events <= 3.5.9 - Unauthenticated Insecure Direct Object Reference

medium

The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.5.9 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.5.9
Fixed in:
3.6.0
Disclosed:
Dec 18, 2025

CVE-2025-68979 on NVD →

Simple Calendar &#8211; Google Calendar Plugin [google-calendar-events] < 3.4.3

unknown

[en] The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

Affected:
up to 3.4.3
Fixed in:
3.4.3
Disclosed:
Sep 25, 2024

CVE-2024-8549 on NVD →

Simple Calendar – Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scripting

medium

The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...

CVSS:
6.1
Affected:
up to 3.4.2
Fixed in:
3.4.3
Disclosed:
Sep 24, 2024

CVE-2024-8549 on NVD →

Simple Calendar &#8211; Google Calendar Plugin [google-calendar-events] < 3.2.8

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Simple Calendar Simple Calendar – Google Calendar Plugin allows Stored XSS.This issue affects Simple Calendar – Google Calendar Plugin: from n/a through 3.2.6.

Affected:
up to 3.2.8
Fixed in:
3.2.8
Disclosed:
Dec 14, 2023

CVE-2023-49151 on NVD →

Google Calendar Events <= 3.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

medium

The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...

CVSS:
6.4
Affected:
up to 3.2.7
Fixed in:
3.2.8
Disclosed:
Nov 28, 2023

CVE-2023-49151 on NVD →

Simple Calendar &#8211; Google Calendar Plugin [google-calendar-events] < 3.2.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Simple Calendar – Google Calendar Plugin <= 3.2.5 versions.

Affected:
up to 3.2.6
Fixed in:
3.2.6
Disclosed:
Oct 24, 2023

CVE-2023-46189 on NVD →

Simple Calendar <= 3.2.4 - Cross-Site Request Forgery via duplicate_feed

medium

The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 3.2.5 (exclusive). This is due to missing or incorrect nonce validation on the duplicate_feed function. This makes it possible for unauthenticated attackers to duplicate feeds via a forged...

CVSS:
4.3
Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Oct 20, 2023

Simple Calendar &#8211; Google Calendar Plugin [google-calendar-events] < 3.2.5

unknown

The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 3.2.5 (exclusive). This is due to missing or incorrect nonce validation on the duplicate_feed function. This makes it possible for unauthenticated attackers to duplicate feeds via a forged...

Affected:
up to 3.2.5
Fixed in:
3.2.5
Disclosed:
Oct 20, 2023

Google Calendar Events <= 3.2.5 - Cross-Site Request Forgery via bulk_actions

medium

The Google Calendar Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.5. This is due to missing nonce validation on the 'bulk_actions' function. This makes it possible for unauthenticated attackers to perform bulk actions via a forged request granted they can...

CVSS:
4.3
Affected:
up to 3.2.5
Fixed in:
3.2.6
Disclosed:
Oct 18, 2023

CVE-2023-46189 on NVD →

Simple Calendar <= 3.1.42 - Cross-Site Request Forgery to Transient Cache Clearing

medium

The Simple Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.42. This is due to missing nonce validation on the clear_cache() function used to clear the plugin's transients. This makes it possible for unauthenticated attackers to clear the plugin's transient...

CVSS:
4.3
Affected:
up to 3.1.42
Fixed in:
3.1.43
Disclosed:
May 11, 2023

Simple Calendar &#8211; Google Calendar Plugin [google-calendar-events] < 3.1.43

unknown

The Simple Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.42. This is due to missing nonce validation on the clear_cache() function used to clear the plugin's transients. This makes it possible for unauthenticated attackers to clear the plugin's transient...

Affected:
up to 3.1.43
Fixed in:
3.1.43
Disclosed:
May 11, 2023

Simple Calendar &#8211; Google Calendar Plugin [google-calendar-events] < 2.0.4

unknown

[en] Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gce_feed_ids parameter in a gce_ajax action to wp-admin/admin-ajax.php.

Affected:
up to 2.0.4
Fixed in:
2.0.4
Disclosed:
Oct 16, 2014

CVE-2014-7138 on NVD →

Simple Calendar – Google Calendar Plugin < 2.0.4 - Reflected Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gce_feed_ids parameter in a gce_ajax action to wp-admin/admin-ajax.php.

CVSS:
6.1
Affected:
up to 2.0.4
Fixed in:
2.0.4
Disclosed:
Oct 8, 2014

CVE-2014-7138 on NVD →

Simple Calendar &#8211; Google Calendar Plugin [google-calendar-events] < 3.2.5

unknown

The Simple Calendar &ndash; Google Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 3.2.5 (exclusive). This is due to missing or incorrect nonce validation on the duplicate_feed function. This makes it possible for unauthenticated attackers to duplicate feeds via a...

Affected:
up to 3.2.5
Fixed in:
3.2.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database