
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24636 is a Missing Authorization (Broken Access Control) vulnerability in the Sugar Calendar (Lite) WordPress plugin developed by Syed Balkhi. It allows authenticated attackers with low privileges (Contributor/Developer level) to exploit incorrectly configured access control security levels, potentially performing unauthorized actions. The vulnerability affects Sugar Calendar (Lite) versions up to and including 3.9.1, with version 3.10.0 serving as the patched release. It was first reported on January 23, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Patchstack (Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before executing certain privileged actions. An attacker with at least Contributor or Developer-level access to a WordPress site can exploit this flaw by sending crafted requests to plugin functionality that lacks proper authorization checks. No complex conditions or user interaction are required beyond having a low-privileged account on the target WordPress installation (Patchstack).
Successful exploitation allows a low-privileged authenticated user to perform actions beyond their intended authorization level, resulting in unauthorized integrity modifications (e.g., manipulating calendar events or plugin settings). There is no direct confidentiality or availability impact based on the CVSS assessment. The scope is limited to the affected WordPress instance, with no evidence of lateral movement potential beyond the plugin's functionality (Patchstack).
The vulnerability requires low-level authentication (Contributor or Developer role) and no user interaction, making it relatively straightforward to exploit for anyone with a valid account on the target site. The EPSS score is approximately 0.025% (0.000250), indicating a low probability of active exploitation in the wild. No public proof-of-concept exploit code, exploit kit integration, or in-the-wild exploitation has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale (Patchstack).
current_user_can() calls).wp-admin/admin-ajax.php with the relevant action parameter) that triggers a privileged plugin function without the required authorization check.wp-admin/admin-ajax.php with Sugar Calendar-specific action parameters from low-privileged user accounts; unexpected modifications to calendar event records in the WordPress database.The vendor has released Sugar Calendar (Lite) version 3.10.0 to address this vulnerability; all users should update immediately. No configuration-based workaround is documented — upgrading to version 3.10.0 or later is the recommended and only confirmed remediation. WordPress site administrators using Patchstack can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."