WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Simple Calendar – Google Calendar Plugin

Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.

7Reported vulnerabilities
6.4Highest CVSS score
4.1.0Latest version
50,000+Active installs

What to do now

Update Simple Calendar – Google Calendar Plugin to 3.6.0 or later. 7 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 3, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2014-7138 Medium 4.3 2.4% 2.0.3.1 and earlier 2.0.4 October 16, 2014
CVE-2023-49151 Medium 6.4 0.4% 3.2.7 and earlier 3.2.8 November 28, 2023
CVE-2024-8549 Medium 6.1 0.5% Before 3.4.3 3.4.3 September 25, 2024
CVE-2025-68979 Medium 5.3 0.3% 3.5.9 and earlier 3.6.0 December 18, 2025
WF-38adede2-73ca-470c-8ace-4f5bbec51d28 Medium 4.3 Before 3.2.5 3.2.5 October 20, 2023
CVE-2023-46189 Medium 4.3 0.3% 3.2.5 and earlier 3.2.6 October 18, 2023
WF-248b74d3-5228-473d-a79a-743566898606 Medium 4.3 3.1.42 and earlier 3.1.43 May 11, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.