CVE-2023-6360
HIGH EXPLOITED NUCLEIWordPress My Calendar <3.4.22 - SQL Injection
Title source: llmDescription
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.
Exploits (1)
Nuclei Templates (1)
WordPress My Calendar <3.4.22 - SQL Injection
CRITICALVERIFIEDby xxcdd
FOFA:
"wordpress" && body="wp-content/plugins/my-calendar"
Scores
CVSS v3
8.6
EPSS
0.8806
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Details
VulnCheck KEV
2025-12-19
CWE
CWE-89
Status
published
Products (1)
joedolson/my_calendar
< 3.4.22
Published
Nov 30, 2023
Tracked Since
Feb 18, 2026