
CP Multi View Events Calendar Security & Risk Analysis
wordpress.org/plugins/cp-multi-view-calendarA powerful and flexible WordPress event calendar plugin that lets you display your events in multiple calendar views, just like Google Calendar.
Is CP Multi View Events Calendar Safe to Use in 2026?
Use With Caution
Score 63/100CP Multi View Events Calendar has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "cp-multi-view-calendar" plugin v1.4.34 exhibits a mixed security posture. While it demonstrates good practices like a high percentage of prepared SQL statements and properly escaped output, several significant concerns exist. The presence of `unserialize` in its code signals a potential for deserialization vulnerabilities, especially if user-controlled data is involved. Furthermore, the taint analysis reveals a concerning five high-severity flows with unsanitized paths, indicating potential for various injection attacks if these flows are not properly handled.
The plugin's vulnerability history is particularly alarming, with six known CVEs, including one critical and one high severity, and one critical vulnerability remaining unpatched. The common vulnerability types such as Missing Authorization, Improper Authorization, Cross-site Scripting (XSS), and SQL Injection are deeply concerning and suggest recurring weaknesses in how user input is validated and access is controlled. The recent nature of the last vulnerability (2025-09-22) also suggests ongoing security challenges.
In conclusion, despite some positive aspects in its static analysis regarding SQL and output handling, the presence of dangerous functions like `unserialize`, high-severity taint flows, and a history of multiple, severe, and unpatched vulnerabilities make this plugin a significant risk. Users should exercise extreme caution.
Key Concerns
- 1 Unpatched CVE (Critical)
- 5 High severity taint flows
- 1 Known CVE (High)
- Dangerous function: unserialize
- 2 Known CVEs (Medium)
- 2 Known CVEs (Low)
CP Multi View Events Calendar Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
CP Multi View Event Calendar <= 1.4.32 - Missing Authorization
CP Multi View Event Calendar <= 1.4.10 - Missing Authentication leading to Authenticated (Subscriber+) Private Form Submission
CP Multi View Event Calendar <= 1.4.13 - Insufficient Authorization
Calendar Event Multi View <= 1.4.06 - Missing Authorization to Stored Cross-Site Scripting
Calendar Event Multi View <= 1.3.99 - Reflected Cross-Site Scripting
Calendar Event Multi View < 1.0.2 - SQL Injection
CP Multi View Events Calendar Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CP Multi View Events Calendar Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Scheduled Events 1
Maintenance & Trust
CP Multi View Events Calendar Maintenance & Trust
Maintenance Signals
Community Trust
CP Multi View Events Calendar Alternatives
My Calendar – Accessible Event Manager
my-calendar
Accessible WordPress event calendar plugin. Manage single or recurring events, event venues, and display your calendar anywhere on your site.
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered)
wp-event-solution
Create and manage events with a flexible WordPress events calendar plugin. Add recurring events, RSVP, ticket booking, and WooCommerce ticket selling …
WP FullCalendar
wp-fullcalendar
Uses the FullCalendar library to create a stunning calendar view of events, posts and other custom post types
EventPrime – Events Calendar, Bookings and Tickets
eventprime-event-calendar-management
Modern Events Calendar plugin ❤️ for creating free or paid events. Supports Event Types, Bookings, Tickets, Venues, Performers, and a lot more.
Quick Event Manager
quick-event-manager
Simple event manager. No messing about, just add events and a shortcode and the plugin does the rest for you.
CP Multi View Events Calendar Developer Profile
34 plugins · 89K total installs
How We Detect CP Multi View Events Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cp-multi-view-calendar/cp-main-class.inc.php/wp-content/plugins/cp-multi-view-calendar/classes/cp-base-class.inc.php/wp-content/plugins/cp-multi-view-calendar/cp-feedback.php/wp-content/plugins/cp-multi-view-calendar/banner.phpHTML / DOM Fingerprints
abcreasonblockSTART: activation redirectionEND: activation redirectiondata-slug="cp-multi-view-calendar"cpmvc_ajax_object