plugin

Sugar Calendar Lite Vulnerabilities

4 known security issues reported for the Sugar Calendar Lite WordPress plugin. Most recent disclosed Jan 23, 2026.

2 medium

Running Sugar Calendar Lite on your site? Check whether your installed version is affected.

Scan your site free

Sugar Calendar &#8211; Events Calendar, Event Tickets, and Events Management Platform [sugar-calendar-lite] <= 3.10.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in Syed Balkhi Sugar Calendar (Lite) sugar-calendar-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sugar Calendar (Lite): from n/a through <= 3.10.1.

Affected:
up to 3.10.1
Fix:
No patched version reported
Disclosed:
Jan 23, 2026

CVE-2026-24636 on NVD →

Sugar Calendar (Lite) <= 3.9.1 - Missing Authorization

medium

The Sugar Calendar (Lite) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.9.1. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 3.9.1
Fixed in:
3.10.0
Disclosed:
Jan 5, 2026

CVE-2026-24636 on NVD →

Sugar Calendar &#8211; Events Calendar, Event Tickets, and Events Management Platform [sugar-calendar-lite] < 3.4.0

unknown

[en] The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.3.0. This makes it possible for unauthenticated attackers to inject ar...

Affected:
up to 3.4.0
Fixed in:
3.4.0
Disclosed:
Nov 26, 2024

CVE-2024-10878 on NVD →

Sugar Calendar (Lite) <= 3.3.0 - Reflected Cross-Site Scripting

medium

The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.3.0. This makes it possible for unauthenticated attackers to inject arbitra...

CVSS:
6.1
Affected:
up to 3.3.0
Fixed in:
3.4.0
Disclosed:
Nov 19, 2024

CVE-2024-10878 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database