
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22351 is a Missing Authorization (Broken Access Control) vulnerability in the WP FullCalendar WordPress plugin developed by Marcus (aka @msykes). It allows unauthenticated remote attackers to exploit incorrectly configured access control security levels, classified under CWE-862. The vulnerability affects WP FullCalendar versions up to and including 1.6, with no official patch available as of the time of disclosure. It was reported by Doan Dinh Van on November 30, 2025, and published on February 11, 2026, with a CVSS v3.1 base score of 7.5 (High) (Patchstack, Feedly).
The root cause is a missing authorization check (CWE-862) in the WP FullCalendar plugin, where one or more functions fail to verify whether the requesting user has the appropriate permissions before executing privileged actions. This falls under OWASP Top 10 category A1: Broken Access Control. An unauthenticated attacker can send crafted network requests to trigger these unprotected functions without any prior authentication or elevated privileges. No user interaction is required, and the attack complexity is low, making it straightforward to exploit at scale (Patchstack).
Successful exploitation results in a high confidentiality impact, as unauthenticated attackers can access data or functionality that should be restricted to privileged users. Integrity and availability are not directly impacted according to the CVSS scoring. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of their traffic or popularity (Patchstack).
No official patch is currently available, leaving all sites running WP FullCalendar version 1.6 or earlier exposed. The EPSS score is approximately 0.017% (0.000170), indicating a currently low but non-negligible probability of exploitation in the near term. There is no confirmed evidence of active in-the-wild exploitation or known public PoC code at this time, and the vulnerability has not been added to the CISA KEV catalog. However, Patchstack classifies it as expected to be exploited and suitable for mass-exploit campaigns (Patchstack, Feedly).
/wp-content/plugins/wp-fullcalendar/readme.txt.current_user_can() or nonce verification checks.wp-admin/admin-ajax.php with the relevant action parameter) targeting the unprotected function.wp-admin/admin-ajax.php with action parameters associated with WP FullCalendar plugin functions; repeated requests from a single IP or distributed IPs in a short timeframe.No official patch from the plugin developer is currently available for WP FullCalendar version 1.6 or earlier. Patchstack has issued a virtual patching/mitigation rule that blocks both legitimate and illegitimate requests to the vulnerable functionality until an official fix is released — users of the Patchstack service benefit from this protection automatically. Site administrators are advised to deactivate and remove the WP FullCalendar plugin until an official patched version is published, or consult their hosting provider for assistance (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."