VR Calendar <= 2.4.7 - Cross-Site Request Forgery to Calendar Sync
medium
The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.7. This is due to missing or incorrect nonce validation on the syncCalendar() function. This makes it possible for unauthenticated attackers to trigger a calendar sync via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 2.4.7
- Fix:
- No patched version reported
- Disclosed:
- Jun 26, 2025
CVE-2025-5936 on NVD →
VR Calendar [vr-calendar-sync] < 2.4.5 (closed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar allows PHP Local File Inclusion.This issue affects VR Calendar: from n/a through 2.4.0.
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.5
- Disclosed:
- Oct 5, 2024
CVE-2024-44013 on NVD →
VR Calendar <= 2.4.4 - Unauthenticated Local File Inclusion
critical
The VR Calendar plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access cont...
- CVSS:
- 9.8
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.5
- Disclosed:
- Sep 24, 2024
CVE-2024-44013 on NVD →
VR Calendar <= 2.3.3 - Cross-Site Request Forgery
high
The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify calendars as well as the plugin settings, via fo...
- CVSS:
- 8.8
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.4
- Disclosed:
- Nov 3, 2022
CVE-2022-3852 on NVD →
VR Calendar [vr-calendar-sync] < 2.3.4 (closed)
unknown
[en] The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify calendars as well as the plugin settings, v...
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Nov 3, 2022
CVE-2022-3852 on NVD →
VR Calendar [vr-calendar-sync] < 2.3.2 (closed)
unknown
[en] The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Aug 15, 2022
CVE-2022-2314 on NVD →
VR Calendar <= 2.4.4 - Authenticated (Administrator+) Local File Inclusion
medium
The VR Calendar plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.4. This makes it possible for administrator-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access cont...
- CVSS:
- 6.8
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.5
- Disclosed:
- Jul 28, 2022
VR Calendar [vr-calendar-sync] < 2.4.5 (closed)
unknown
The VR Calendar plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.4. This makes it possible for administrator-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access cont...
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.5
- Disclosed:
- Jul 28, 2022
VR Calendar <= 2.3.1 - Reflected Cross-Site Scripting
medium
The VR Calendar for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vrc_msg' and 'vrc_msg_type' parameters in versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Jul 26, 2022
VR Calendar [vr-calendar-sync] < 2.3.2 (closed)
unknown
The VR Calendar for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vrc_msg' and 'vrc_msg_type' parameters in versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- Affected:
- up to 2.3.2
- Fixed in:
- 2.3.2
- Disclosed:
- Jul 26, 2022
VR Calendar <= 2.3.1 - Unauthenticated Remote Code Execution
critical
The VR Calendar plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.2.2 via the handleCommands() function that accepts user supplied input via the 'vrc_cmd' parameter that is passed to call_user_func(). This allows unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.2
- Disclosed:
- Jul 22, 2022
CVE-2022-2314 on NVD →
VR Calendar [vr-calendar-sync] < 2.4.5 (closed)
unknown
The plugin does not validate user input before using it in a require statement, which could allow high privilege users to perform LFI attacks. The attack could also be performed via a CSRF vector by making a logged in admin open a malicious link
- Affected:
- up to 2.4.5
- Fixed in:
- 2.4.5
VR Calendar [vr-calendar-sync] < 2.3.1 (closed)
unknown
The plugin does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.1
VR Calendar [vr-calendar-sync] <= 2.4.7 (unfixed + closed)
unknown
- Affected:
- up to 2.4.7
- Fix:
- No patched version reported
CVE-2025-5936 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database