Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-22351
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-22351 is a Missing Authorization (Broken Access Control) vulnerability in the WP FullCalendar WordPress plugin developed by Marcus (aka @msykes). It allows unauthenticated remote attackers to exploit incorrectly configured access control security levels, classified under CWE-862. The vulnerability affects WP FullCalendar versions up to and including 1.6, with no official patch available as of the time of disclosure. It was reported by Doan Dinh Van on November 30, 2025, and published on February 11, 2026, with a CVSS v3.1 base score of 7.5 (High) (Patchstack, Feedly).

Technical details

The root cause is a missing authorization check (CWE-862) in the WP FullCalendar plugin, where one or more functions fail to verify whether the requesting user has the appropriate permissions before executing privileged actions. This falls under OWASP Top 10 category A1: Broken Access Control. An unauthenticated attacker can send crafted network requests to trigger these unprotected functions without any prior authentication or elevated privileges. No user interaction is required, and the attack complexity is low, making it straightforward to exploit at scale (Patchstack).

Impact

Successful exploitation results in a high confidentiality impact, as unauthenticated attackers can access data or functionality that should be restricted to privileged users. Integrity and availability are not directly impacted according to the CVSS scoring. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of their traffic or popularity (Patchstack).

Exploitability

No official patch is currently available, leaving all sites running WP FullCalendar version 1.6 or earlier exposed. The EPSS score is approximately 0.017% (0.000170), indicating a currently low but non-negligible probability of exploitation in the near term. There is no confirmed evidence of active in-the-wild exploitation or known public PoC code at this time, and the vulnerability has not been added to the CISA KEV catalog. However, Patchstack classifies it as expected to be exploited and suitable for mass-exploit campaigns (Patchstack, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP FullCalendar plugin (version ≤ 1.6) using tools like WPScan, Shodan, or by checking publicly accessible plugin metadata at /wp-content/plugins/wp-fullcalendar/readme.txt.
  2. Identify unprotected endpoints: Analyze the plugin's source code or use fuzzing tools to locate AJAX actions or REST API endpoints registered without proper current_user_can() or nonce verification checks.
  3. Craft malicious request: Send an unauthenticated HTTP request (e.g., a POST to wp-admin/admin-ajax.php with the relevant action parameter) targeting the unprotected function.
  4. Achieve unauthorized access: The server processes the request without authorization checks, returning restricted data or performing privileged operations on behalf of the unauthenticated attacker (Patchstack).

Indicators of compromise

  • Network: Unusual unauthenticated POST requests to wp-admin/admin-ajax.php with action parameters associated with WP FullCalendar plugin functions; repeated requests from a single IP or distributed IPs in a short timeframe.
  • Logs: WordPress access logs showing unauthenticated requests to plugin-specific AJAX endpoints returning HTTP 200 responses with sensitive data; absence of authentication cookies in requests that trigger privileged actions.
  • File System: Unexpected modifications to WordPress files or database entries following suspicious plugin endpoint access.

Mitigation and workarounds

No official patch from the plugin developer is currently available for WP FullCalendar version 1.6 or earlier. Patchstack has issued a virtual patching/mitigation rule that blocks both legitimate and illegitimate requests to the vulnerable functionality until an official fix is released — users of the Patchstack service benefit from this protection automatically. Site administrators are advised to deactivate and remove the WP FullCalendar plugin until an official patched version is published, or consult their hosting provider for assistance (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-88788MEDIUM6.8
  • text-styler
NoNoSep 19, 2026
CVE-2026-9858MEDIUM4.3
  • wc-partial-shipment
NoYesSep 19, 2026
CVE-2026-9766MEDIUM4.3
  • empik-for-woocommerce
NoYesSep 19, 2026
CVE-2026-9613MEDIUM4.3
  • datalogics
NoYesSep 19, 2026
CVE-2026-87848LOW3.7
  • mpcx-lightbox
NoNoSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management