CVE-2022-38067 MEDIUM

CVE-2022-38067: WordPress Event Calendar – Calendar plugin <= 1.4.6 - Unauthenticated Event Deletion vulnerability

Vendor Totalsoft
Product Event Calendar – Calendar (WordPress plugin)
Weakness CWE-264
Published September 9, 2022
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

The Event Calendar plugin for WordPress versions up to 1.4.6 contains a vulnerability that allows unauthenticated attackers to modify calendar data and disrupt service. The vulnerability requires no user interaction and can be exploited remotely over the network. Site administrators should update the plugin to a version newer than 1.4.6.

What an attacker can do

03Attacker Capabilities

Modify calendar events and disrupt calendar functionality without authentication.

Potential impact on your site

04Site Impact

Calendar events can be altered or deleted by attackers, disrupting scheduling and availability for site visitors.

Conditions required to exploit

05Prerequisites

Network access to the WordPress site; no authentication or user interaction required.

Key dates

06Disclosure timeline

September 9, 2022 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE