plugin

Vr Calendar Sync Vulnerabilities

14 known security issues reported for the Vr Calendar Sync WordPress plugin. Most recent disclosed Jun 26, 2025.

2 critical 1 high 3 medium

Running Vr Calendar Sync on your site? Check whether your installed version is affected.

Scan your site free

VR Calendar <= 2.4.7 - Cross-Site Request Forgery to Calendar Sync

medium

The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.7. This is due to missing or incorrect nonce validation on the syncCalendar() function. This makes it possible for unauthenticated attackers to trigger a calendar sync via a forged request granted...

CVSS:
4.3
Affected:
up to 2.4.7
Fix:
No patched version reported
Disclosed:
Jun 26, 2025

CVE-2025-5936 on NVD →

VR Calendar [vr-calendar-sync] < 2.4.5 (closed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar allows PHP Local File Inclusion.This issue affects VR Calendar: from n/a through 2.4.0.

Affected:
up to 2.4.5
Fixed in:
2.4.5
Disclosed:
Oct 5, 2024

CVE-2024-44013 on NVD →

VR Calendar <= 2.4.4 - Unauthenticated Local File Inclusion

critical

The VR Calendar plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access cont...

CVSS:
9.8
Affected:
up to 2.4.4
Fixed in:
2.4.5
Disclosed:
Sep 24, 2024

CVE-2024-44013 on NVD →

VR Calendar <= 2.3.3 - Cross-Site Request Forgery

high

The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify calendars as well as the plugin settings, via fo...

CVSS:
8.8
Affected:
up to 2.3.3
Fixed in:
2.3.4
Disclosed:
Nov 3, 2022

CVE-2022-3852 on NVD →

VR Calendar [vr-calendar-sync] < 2.3.4 (closed)

unknown

[en] The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify calendars as well as the plugin settings, v...

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Nov 3, 2022

CVE-2022-3852 on NVD →

VR Calendar [vr-calendar-sync] < 2.3.2 (closed)

unknown

[en] The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Aug 15, 2022

CVE-2022-2314 on NVD →

VR Calendar <= 2.4.4 - Authenticated (Administrator+) Local File Inclusion

medium

The VR Calendar plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.4. This makes it possible for administrator-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access cont...

CVSS:
6.8
Affected:
up to 2.4.4
Fixed in:
2.4.5
Disclosed:
Jul 28, 2022

VR Calendar [vr-calendar-sync] < 2.4.5 (closed)

unknown

The VR Calendar plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.4. This makes it possible for administrator-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access cont...

Affected:
up to 2.4.5
Fixed in:
2.4.5
Disclosed:
Jul 28, 2022

VR Calendar <= 2.3.1 - Reflected Cross-Site Scripting

medium

The VR Calendar for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vrc_msg' and 'vrc_msg_type' parameters in versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
6.1
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Jul 26, 2022

VR Calendar [vr-calendar-sync] < 2.3.2 (closed)

unknown

The VR Calendar for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'vrc_msg' and 'vrc_msg_type' parameters in versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 2.3.2
Fixed in:
2.3.2
Disclosed:
Jul 26, 2022

VR Calendar <= 2.3.1 - Unauthenticated Remote Code Execution

critical

The VR Calendar plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.2.2 via the handleCommands() function that accepts user supplied input via the 'vrc_cmd' parameter that is passed to call_user_func(). This allows unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 2.3.1
Fixed in:
2.3.2
Disclosed:
Jul 22, 2022

CVE-2022-2314 on NVD →

VR Calendar [vr-calendar-sync] < 2.4.5 (closed)

unknown

The plugin does not validate user input before using it in a require statement, which could allow high privilege users to perform LFI attacks. The attack could also be performed via a CSRF vector by making a logged in admin open a malicious link

Affected:
up to 2.4.5
Fixed in:
2.4.5

VR Calendar [vr-calendar-sync] < 2.3.1 (closed)

unknown

The plugin does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting

Affected:
up to 2.3.1
Fixed in:
2.3.1

VR Calendar [vr-calendar-sync] <= 2.4.7 (unfixed + closed)

unknown
Affected:
up to 2.4.7
Fix:
No patched version reported

CVE-2025-5936 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database