Spiffy Calendar <= 5.0.7 - Missing Authorization
medium
The Spiffy Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.0.7
- Fixed in:
- 5.0.8
- Disclosed:
- Jan 5, 2026
CVE-2025-68523 on NVD →
Spiffy Calendar [spiffy-calendar] <= 5.0.7 (unfixed)
unknown
[en] Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spiffy Calendar: from n/a through <= 5.0.7.
- Affected:
- up to 5.0.7
- Fix:
- No patched version reported
- Disclosed:
- Dec 24, 2025
CVE-2025-68523 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.13
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.12.
- Affected:
- up to 4.9.13
- Fixed in:
- 4.9.13
- Disclosed:
- Sep 17, 2024
CVE-2024-43969 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.14
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Stored XSS.This issue affects Spiffy Calendar: from n/a through 4.9.13.
- Affected:
- up to 4.9.14
- Fixed in:
- 4.9.14
- Disclosed:
- Sep 15, 2024
CVE-2024-45457 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.14
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.13.
- Affected:
- up to 4.9.14
- Fixed in:
- 4.9.14
- Disclosed:
- Sep 15, 2024
CVE-2024-45458 on NVD →
Spiffy Calendar <= 4.9.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Spiffy Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.9.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 4.9.13
- Fixed in:
- 4.9.14
- Disclosed:
- Sep 12, 2024
CVE-2024-45457 on NVD →
Spiffy Calendar <= 4.9.13 - Reflected Cross-Site Scripting
medium
The Spiffy Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.9.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...
- CVSS:
- 6.1
- Affected:
- up to 4.9.13
- Fixed in:
- 4.9.14
- Disclosed:
- Sep 12, 2024
CVE-2024-45458 on NVD →
Spiffy Calendar <= 4.9.12 - Authenticated (Admin+) SQL Injection
medium
The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.9.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level acc...
- CVSS:
- 4.9
- Affected:
- up to 4.9.12
- Fixed in:
- 4.9.13
- Disclosed:
- Aug 28, 2024
CVE-2024-43969 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.12
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.11.
- Affected:
- up to 4.9.12
- Fixed in:
- 4.9.12
- Disclosed:
- Jul 22, 2024
CVE-2024-38692 on NVD →
Spiffy Calendar <= 4.9.11 - Authenticated (Administrator+) SQL Injection
critical
The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access...
- CVSS:
- 9.1
- Affected:
- up to 4.9.11
- Fixed in:
- 4.9.12
- Disclosed:
- Jul 10, 2024
CVE-2024-38692 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.11
unknown
[en] Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.
- Affected:
- up to 4.9.11
- Fixed in:
- 4.9.11
- Disclosed:
- Jun 4, 2024
CVE-2024-30528 on NVD →
Spiffy Calendar <= 4.9.10 - Missing Authorization
medium
The Spiffy Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the admin_menu_output() function in versions up to, and including, 4.9.10. This makes it possible for authenticated attackers, with contributor-level access and above, to update an option.
- CVSS:
- 4.3
- Affected:
- up to 4.9.10
- Fixed in:
- 4.9.11
- Disclosed:
- Mar 29, 2024
CVE-2024-30528 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.10
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Reflected XSS.This issue affects Spiffy Calendar: from n/a through 4.9.7.
- Affected:
- up to 4.9.10
- Fixed in:
- 4.9.10
- Disclosed:
- Mar 29, 2024
CVE-2024-30427 on NVD →
Spiffy Calendar <= 4.9.7 - Reflected Cross-Site Scripting
medium
The Spiffy Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...
- CVSS:
- 6.1
- Affected:
- up to 4.9.7
- Fixed in:
- 4.9.10
- Disclosed:
- Mar 28, 2024
CVE-2024-30427 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.9
unknown
[en] The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.
- Affected:
- up to 4.9.9
- Fixed in:
- 4.9.9
- Disclosed:
- Feb 27, 2024
CVE-2024-0855 on NVD →
Spiffy Calendar <= 4.9.8 - Insufficient Authorization
medium
The Spiffy Calendar plugin for WordPress is vulnerable to unauthorized modification of data due insufficient restrictions on the event_author parameter in all versions up to, and including, 4.9.8. This makes it possible for authenticated attackers, with contributor-level access and above, to make an event appear as tho...
- CVSS:
- 4.3
- Affected:
- up to 4.9.8
- Fixed in:
- 4.9.9
- Disclosed:
- Jan 12, 2024
CVE-2024-0855 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.6
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar allows Stored XSS.This issue affects Spiffy Calendar: from n/a through 4.9.5.
- Affected:
- up to 4.9.6
- Fixed in:
- 4.9.6
- Disclosed:
- Dec 14, 2023
CVE-2023-49745 on NVD →
Spiffy Calendar <= 4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Spiffy Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to 4.9.6 (exclusive) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level an...
- CVSS:
- 6.4
- Affected:
- up to 4.9.5
- Fixed in:
- 4.9.6
- Disclosed:
- Dec 1, 2023
CVE-2023-49745 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.6
unknown
The Spiffy Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to 4.9.6 (exclusive) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level an...
- Affected:
- up to 4.9.6
- Fixed in:
- 4.9.6
- Disclosed:
- Dec 1, 2023
Spiffy Calendar [spiffy-calendar] < 4.9.2
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.1.
- Affected:
- up to 4.9.2
- Fixed in:
- 4.9.2
- Disclosed:
- Nov 3, 2023
CVE-2022-46859 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.4
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Spiffy Plugins Spiffy Calendar plugin <= 4.9.3 versions.
- Affected:
- up to 4.9.4
- Fixed in:
- 4.9.4
- Disclosed:
- Aug 18, 2023
CVE-2023-32122 on NVD →
Spiffy Calendar <= 4.9.3 - Reflected Cross-Site Scripting via page parameter
medium
The Spiffy Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 4.7
- Affected:
- up to 4.9.4
- Fixed in:
- 4.9.4
- Disclosed:
- May 3, 2023
CVE-2023-32122 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.4
unknown
The Spiffy Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 4.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- Affected:
- up to 4.9.4
- Fixed in:
- 4.9.4
- Disclosed:
- May 3, 2023
Spiffy Calendar <= 4.9.1 - Authenticated (Contributor+) SQL Injection
high
The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter among others in versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...
- CVSS:
- 8.8
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.2
- Disclosed:
- Dec 16, 2022
CVE-2022-46859 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.2
unknown
The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter among others in versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...
- Affected:
- up to 4.9.2
- Fixed in:
- 4.9.2
- Disclosed:
- Dec 16, 2022
Spiffy Calendar [spiffy-calendar] < 4.9.1
unknown
[en] Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- May 20, 2022
CVE-2022-29434 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0).
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Feb 21, 2022
CVE-2022-25599 on NVD →
Spiffy Calendar <= 4.9.0 - Edit/Delete event via IDOR
medium
Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.
- CVSS:
- 6.3
- Affected:
- up to 4.9.0
- Fixed in:
- 4.9.1
- Disclosed:
- Feb 10, 2022
CVE-2022-29434 on NVD →
Spiffy Calendar <= 4.9.0 - Event deletion via Cross-Site Request Forgery
medium
Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress plugin (versions <= 4.9.0).
- CVSS:
- 5.4
- Affected:
- up to 4.9.0
- Fixed in:
- 4.9.1
- Disclosed:
- Feb 10, 2022
CVE-2022-25599 on NVD →
Spiffy Calendar [spiffy-calendar] < 4.9.1
unknown
Edit/Delete event via IDOR vulnerability discovered in WordPress Spiffy Calendar plugin (versions <= 4.9.0) by Ex.Mi (Patchstack).
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Feb 10, 2022
Spiffy Calendar [spiffy-calendar] < 4.9.1
unknown
Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities discovered in WordPress Spiffy Calendar plugin (versions <= 4.9.0) by Ex.Mi (Patchstack).
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Feb 10, 2022
Spiffy Calendar [spiffy-calendar] < 4.9.1
unknown
Admin+ Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Spiffy Calendar plugin (versions <= 4.9.0) by Ex.Mi (Patchstack).
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Feb 10, 2022
Spiffy Calendar [spiffy-calendar] < 4.9.1
unknown
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Spiffy Calendar plugin (versions <= 4.9.0) by Ex.Mi (Patchstack).
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Feb 10, 2022
Spiffy Calendar [spiffy-calendar] < 3.3.0
unknown
[en] Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
- Disclosed:
- Jun 5, 2017
CVE-2017-9420 on NVD →
Spiffy Calendar < 3.3.0 - Reflected Cross-Site Scripting
medium
Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.
- CVSS:
- 6.1
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.0
- Disclosed:
- Jun 2, 2017
CVE-2017-9420 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database