WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Spiffy Calendar

Manage and display your events in a responsive calendar with multiple views, widgets and shortcodes. Color-coded categories and recurrence support.

14Reported vulnerabilities
9.1Highest CVSS score
5.0.11Latest version
2,000+Active installs

What to do now

Update Spiffy Calendar to 5.0.8 or later. 14 of these have a fixed version available. Updating resolves them.

Plugin last updated: April 17, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-38692 Critical 9.1 0.7% 4.9.11 and earlier 4.9.12 July 10, 2024
CVE-2024-0855 Medium 5.3 0.5% Before 4.9.9 4.9.9 February 27, 2024
CVE-2022-46859 High 8.8 0.5% 4.9.1 and earlier 4.9.2 December 16, 2022
CVE-2024-45457 Medium 6.4 0.3% 4.9.13 and earlier 4.9.14 September 12, 2024
CVE-2023-49745 Medium 6.4 0.4% 4.9.5 and earlier 4.9.6 December 1, 2023
CVE-2017-9420 Medium 6.1 1.3% 1.0.0 to 1.0.0 (inclusive)
1.0.1 to 1.0.1 (inclusive)
1.0.2a to 1.0.2a (inclusive)
1.0.3 to 1.0.3 (inclusive)
1.1.0 to 1.1.0 (inclusive)
1.1.1 to 1.1.1 (inclusive)
1.1.2 to 1.1.2 (inclusive)
1.1.3 to 1.1.3 (inclusive)
1.1.4 to 1.1.4 (inclusive)
1.1.5 to 1.1.5 (inclusive)
1.1.6 to 1.1.6 (inclusive)
1.1.7 to 1.1.7 (inclusive)
1.1.8 to 1.1.8 (inclusive)
1.2.0 to 1.2.0 (inclusive)
1.2.1 to 1.2.1 (inclusive)
1.3.0 to 1.3.0 (inclusive)
1.3.1 to 1.3.1 (inclusive)
2.0.0 to 2.0.0 (inclusive)
2.0.1 to 2.0.1 (inclusive)
2.1.0 to 2.1.0 (inclusive)
2.1.1 to 2.1.1 (inclusive)
2.1.2 to 2.1.2 (inclusive)
2.1.3 to 2.1.3 (inclusive)
3.0.0 to 3.0.0 (inclusive)
3.0.1 to 3.0.1 (inclusive)
3.0.2 to 3.0.2 (inclusive)
3.0.3 to 3.0.3 (inclusive)
3.0.4 to 3.0.4 (inclusive)
3.0.5 to 3.0.5 (inclusive)
3.0.6 to 3.0.6 (inclusive)
3.0.7 to 3.0.7 (inclusive)
3.0.8 to 3.0.8 (inclusive)
3.1.0 to 3.1.0 (inclusive)
3.1.1 to 3.1.1 (inclusive)
3.1.2 to 3.1.2 (inclusive)
3.1.3 to 3.1.3 (inclusive)
3.1.4 to 3.1.4 (inclusive)
3.1.5 to 3.1.5 (inclusive)
3.2.0 to 3.2.0 (inclusive)
3.3.0 June 5, 2017
CVE-2024-45458 Medium 6.1 0.3% 4.9.13 and earlier 4.9.14 September 12, 2024
CVE-2024-30427 Medium 6.1 0.4% 4.9.7 and earlier 4.9.10 March 28, 2024
CVE-2022-29434 Medium 5.4 0.7% 4.9.0 and earlier 4.9.1 May 20, 2022
CVE-2024-43969 Medium 4.9 0.4% 4.9.12 and earlier 4.9.13 August 28, 2024
CVE-2023-32122 Medium 4.7 0.3% Before 4.9.4 4.9.4 May 3, 2023
CVE-2025-68523 Medium 4.3 0.2% 5.0.7 and earlier 5.0.8 January 5, 2026
CVE-2024-30528 Medium 4.3 0.3% 4.9.10 and earlier 4.9.11 March 29, 2024
CVE-2022-25599 Medium 4.3 0.4% 4.9.0 and earlier 4.9.1 February 21, 2022

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.