Known vulnerabilities in WP FullCalendar
Uses the FullCalendar library to create a stunning calendar view of events, posts and other custom post types
4Reported vulnerabilities
6.4Highest CVSS score
1.6Latest version
8,000+Active installs
What to do now
Update WP FullCalendar to 1.6 or later.
2 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2022-3891 | Medium | 0.7% | Before 1.5 | 1.5 |
February 13, 2023 |
| CVE-2025-22261 | Medium | 0.3% | 1.5 and earlier | 1.6 |
January 6, 2025 |
| CVE-2026-22351 | Medium | 0.3% | 1.6 and earlier | — | February 11, 2026 |
| CVE-2026-24523 | Medium | 0.3% | 1.6 and earlier | — | January 26, 2026 |