plugin

Spiffy Calendar Vulnerabilities

35 known security issues reported for the Spiffy Calendar WordPress plugin. Most recent disclosed Jan 5, 2026.

1 critical 1 high 12 medium

Running Spiffy Calendar on your site? Check whether your installed version is affected.

Scan your site free

Spiffy Calendar <= 5.0.7 - Missing Authorization

medium

The Spiffy Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 5.0.7
Fixed in:
5.0.8
Disclosed:
Jan 5, 2026

CVE-2025-68523 on NVD →

Spiffy Calendar [spiffy-calendar] <= 5.0.7 (unfixed)

unknown

[en] Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spiffy Calendar: from n/a through <= 5.0.7.

Affected:
up to 5.0.7
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68523 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.13

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.12.

Affected:
up to 4.9.13
Fixed in:
4.9.13
Disclosed:
Sep 17, 2024

CVE-2024-43969 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.14

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Stored XSS.This issue affects Spiffy Calendar: from n/a through 4.9.13.

Affected:
up to 4.9.14
Fixed in:
4.9.14
Disclosed:
Sep 15, 2024

CVE-2024-45457 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.14

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.13.

Affected:
up to 4.9.14
Fixed in:
4.9.14
Disclosed:
Sep 15, 2024

CVE-2024-45458 on NVD →

Spiffy Calendar <= 4.9.13 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Spiffy Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 4.9.13
Fixed in:
4.9.14
Disclosed:
Sep 12, 2024

CVE-2024-45457 on NVD →

Spiffy Calendar <= 4.9.13 - Reflected Cross-Site Scripting

medium

The Spiffy Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.9.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...

CVSS:
6.1
Affected:
up to 4.9.13
Fixed in:
4.9.14
Disclosed:
Sep 12, 2024

CVE-2024-45458 on NVD →

Spiffy Calendar <= 4.9.12 - Authenticated (Admin+) SQL Injection

medium

The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.9.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level acc...

CVSS:
4.9
Affected:
up to 4.9.12
Fixed in:
4.9.13
Disclosed:
Aug 28, 2024

CVE-2024-43969 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.12

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.11.

Affected:
up to 4.9.12
Fixed in:
4.9.12
Disclosed:
Jul 22, 2024

CVE-2024-38692 on NVD →

Spiffy Calendar <= 4.9.11 - Authenticated (Administrator+) SQL Injection

critical

The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access...

CVSS:
9.1
Affected:
up to 4.9.11
Fixed in:
4.9.12
Disclosed:
Jul 10, 2024

CVE-2024-38692 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.11

unknown

[en] Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.

Affected:
up to 4.9.11
Fixed in:
4.9.11
Disclosed:
Jun 4, 2024

CVE-2024-30528 on NVD →

Spiffy Calendar <= 4.9.10 - Missing Authorization

medium

The Spiffy Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the admin_menu_output() function in versions up to, and including, 4.9.10. This makes it possible for authenticated attackers, with contributor-level access and above, to update an option.

CVSS:
4.3
Affected:
up to 4.9.10
Fixed in:
4.9.11
Disclosed:
Mar 29, 2024

CVE-2024-30528 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.10

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.7.

Affected:
up to 4.9.10
Fixed in:
4.9.10
Disclosed:
Mar 29, 2024

CVE-2024-30427 on NVD →

Spiffy Calendar <= 4.9.7 - Reflected Cross-Site Scripting

medium

The Spiffy Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...

CVSS:
6.1
Affected:
up to 4.9.7
Fixed in:
4.9.10
Disclosed:
Mar 28, 2024

CVE-2024-30427 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.9

unknown

[en] The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.

Affected:
up to 4.9.9
Fixed in:
4.9.9
Disclosed:
Feb 27, 2024

CVE-2024-0855 on NVD →

Spiffy Calendar <= 4.9.8 - Insufficient Authorization

medium

The Spiffy Calendar plugin for WordPress is vulnerable to unauthorized modification of data due insufficient restrictions on the event_author parameter in all versions up to, and including, 4.9.8. This makes it possible for authenticated attackers, with contributor-level access and above, to make an event appear as tho...

CVSS:
4.3
Affected:
up to 4.9.8
Fixed in:
4.9.9
Disclosed:
Jan 12, 2024

CVE-2024-0855 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Stored XSS.This issue affects Spiffy Calendar: from n/a through 4.9.5.

Affected:
up to 4.9.6
Fixed in:
4.9.6
Disclosed:
Dec 14, 2023

CVE-2023-49745 on NVD →

Spiffy Calendar <= 4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Spiffy Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to 4.9.6 (exclusive) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level an...

CVSS:
6.4
Affected:
up to 4.9.5
Fixed in:
4.9.6
Disclosed:
Dec 1, 2023

CVE-2023-49745 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.6

unknown

The Spiffy Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to 4.9.6 (exclusive) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level an...

Affected:
up to 4.9.6
Fixed in:
4.9.6
Disclosed:
Dec 1, 2023

Spiffy Calendar [spiffy-calendar] < 4.9.2

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.1.

Affected:
up to 4.9.2
Fixed in:
4.9.2
Disclosed:
Nov 3, 2023

CVE-2022-46859 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.4

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spiffy Plugins Spiffy Calendar plugin <= 4.9.3 versions.

Affected:
up to 4.9.4
Fixed in:
4.9.4
Disclosed:
Aug 18, 2023

CVE-2023-32122 on NVD →

Spiffy Calendar <= 4.9.3 - Reflected Cross-Site Scripting via page parameter

medium

The Spiffy Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
4.7
Affected:
up to 4.9.4
Fixed in:
4.9.4
Disclosed:
May 3, 2023

CVE-2023-32122 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.4

unknown

The Spiffy Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

Affected:
up to 4.9.4
Fixed in:
4.9.4
Disclosed:
May 3, 2023

Spiffy Calendar <= 4.9.1 - Authenticated (Contributor+) SQL Injection

high

The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter among others in versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...

CVSS:
8.8
Affected:
up to 4.9.1
Fixed in:
4.9.2
Disclosed:
Dec 16, 2022

CVE-2022-46859 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.2

unknown

The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter among others in versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...

Affected:
up to 4.9.2
Fixed in:
4.9.2
Disclosed:
Dec 16, 2022

Spiffy Calendar [spiffy-calendar] < 4.9.1

unknown

[en] Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.

Affected:
up to 4.9.1
Fixed in:
4.9.1
Disclosed:
May 20, 2022

CVE-2022-29434 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0).

Affected:
up to 4.9.1
Fixed in:
4.9.1
Disclosed:
Feb 21, 2022

CVE-2022-25599 on NVD →

Spiffy Calendar <= 4.9.0 - Edit/Delete event via IDOR

medium

Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.

CVSS:
6.3
Affected:
up to 4.9.0
Fixed in:
4.9.1
Disclosed:
Feb 10, 2022

CVE-2022-29434 on NVD →

Spiffy Calendar <= 4.9.0 - Event deletion via Cross-Site Request Forgery

medium

Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0).

CVSS:
5.4
Affected:
up to 4.9.0
Fixed in:
4.9.1
Disclosed:
Feb 10, 2022

CVE-2022-25599 on NVD →

Spiffy Calendar [spiffy-calendar] < 4.9.1

unknown

Edit/Delete event via IDOR vulnerability discovered in WordPress Spiffy Calendar plugin (versions <= 4.9.0) by Ex.Mi (Patchstack).

Affected:
up to 4.9.1
Fixed in:
4.9.1
Disclosed:
Feb 10, 2022

Spiffy Calendar [spiffy-calendar] < 4.9.1

unknown

Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities discovered in WordPress Spiffy Calendar plugin (versions <= 4.9.0) by Ex.Mi (Patchstack).

Affected:
up to 4.9.1
Fixed in:
4.9.1
Disclosed:
Feb 10, 2022

Spiffy Calendar [spiffy-calendar] < 4.9.1

unknown

Admin+ Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Spiffy Calendar plugin (versions <= 4.9.0) by Ex.Mi (Patchstack).

Affected:
up to 4.9.1
Fixed in:
4.9.1
Disclosed:
Feb 10, 2022

Spiffy Calendar [spiffy-calendar] < 4.9.1

unknown

Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Spiffy Calendar plugin (versions <= 4.9.0) by Ex.Mi (Patchstack).

Affected:
up to 4.9.1
Fixed in:
4.9.1
Disclosed:
Feb 10, 2022

Spiffy Calendar [spiffy-calendar] < 3.3.0

unknown

[en] Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.

Affected:
up to 3.3.0
Fixed in:
3.3.0
Disclosed:
Jun 5, 2017

CVE-2017-9420 on NVD →

Spiffy Calendar < 3.3.0 - Reflected Cross-Site Scripting

medium

Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.

CVSS:
6.1
Affected:
up to 3.3.0
Fixed in:
3.3.0
Disclosed:
Jun 2, 2017

CVE-2017-9420 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database