
My Calendar – Accessible Event Manager Security & Risk Analysis
wordpress.org/plugins/my-calendarAccessible WordPress event calendar plugin. Manage single or recurring events, event venues, and display your calendar anywhere on your site.
Is My Calendar – Accessible Event Manager Safe to Use in 2026?
Mostly Safe
Score 77/100My Calendar – Accessible Event Manager is generally safe to use. 16 past CVEs were resolved. Keep it updated.
The 'my-calendar' v3.7.6 plugin exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices in many areas, such as a high percentage of SQL prepared statements and properly escaped output, significant concerns remain. The presence of two dangerous functions, specifically 'unserialize,' without explicit mention of sanitization for its usage, warrants caution. Furthermore, the static analysis reveals an attack surface with 3 unprotected entry points out of 24 total, including an unprotected REST API route and two AJAX handlers lacking authentication checks, presenting immediate opportunities for unauthorized actions.
Taint analysis indicates a worrying trend, with 38 high-severity flows identified. These flows, coupled with the presence of dangerous functions, suggest a potential for severe vulnerabilities if not adequately addressed. The plugin's history of 16 known CVEs, although currently all patched, includes past critical and high-severity vulnerabilities. The types of past vulnerabilities are also concerning, encompassing Cross-site Scripting, Missing Authorization, SQL Injection, CSRF, Open Redirect, and Path Traversal, indicating recurring areas of weakness.
In conclusion, while 'my-calendar' v3.7.6 shows strengths in output escaping and SQL query sanitization, the identified unprotected entry points, critical taint flows, and the historical pattern of diverse and severe vulnerabilities suggest a moderate to high risk. Vigilance and thorough auditing of the 'unserialize' usage and the identified taint flows are paramount for mitigating potential security threats.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API route
- High severity taint flows
- Dangerous function: unserialize
- Past critical CVEs (historically)
- Past high severity CVEs (historically)
My Calendar – Accessible Event Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
16 total CVEs
My Calendar – Accessible Event Manager <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
My Calendar <= 3.6.16 - Missing Authorization
My Calendar <= 3.4.23 - Authenticated (Admin+) Stored Cross-Site Scripting via Events
My Calendar <= 3.4.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
My Calendar <= 3.4.21 - Unauthenticated SQL Injection
My Calendar <= 3.4.3 - Cross-Site Request Forgery
My Calendar <= 3.3.24.1 - Cross-Site Request Forgery
My Calendar <= 3.3.16 - Open Redirect
My Calendar <= 3.3.16 - Administrator+ Stored Cross-Site Scripting
My Calendar <= 3.2.17 - Subscriber+ Reflected Cross-Site Scripting
My Calendar <= 3.1.9 - Unauthenticated Cross-Site Scripting
My Calendar <= 2.5.16 - Authenticated Stored Cross-Site Scripting
My Calendar < 2.3.30 - Reflected Cross-Site Scripting
My Calendar <= 2.3.29 - Path Traversal to Remote Code Execution
My Calendar < 2.3.10 - Reflected Cross-Site Scripting
My Calendar < 1.10.5 - Cross-Site Scripting
My Calendar – Accessible Event Manager Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
My Calendar – Accessible Event Manager Attack Surface
AJAX Handlers 11
REST API Routes 1
Shortcodes 12
WordPress Hooks 126
Scheduled Events 2
Maintenance & Trust
My Calendar – Accessible Event Manager Maintenance & Trust
Maintenance Signals
Community Trust
My Calendar – Accessible Event Manager Alternatives
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered)
wp-event-solution
Create and manage events with a flexible WordPress events calendar plugin. Add recurring events, RSVP, ticket booking, and WooCommerce ticket selling …
EventPrime – Events Calendar, Bookings and Tickets
eventprime-event-calendar-management
Modern Events Calendar plugin ❤️ for creating free or paid events. Supports Event Types, Bookings, Tickets, Venues, Performers, and a lot more.
Quick Event Manager
quick-event-manager
Simple event manager. No messing about, just add events and a shortcode and the plugin does the rest for you.
CP Multi View Events Calendar
cp-multi-view-calendar
A powerful and flexible WordPress event calendar plugin that lets you display your events in multiple calendar views, just like Google Calendar.
Simple Event Planner
simple-event-planner
A powerful & flexible plugin to create event listing and event calendar on your website in a simple & elegant way.
My Calendar – Accessible Event Manager Developer Profile
6 plugins · 96K total installs
How We Detect My Calendar – Accessible Event Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.