CVE-2025-67592
Description
Missing Authorization vulnerability in Joe Dolson My Calendar my-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Calendar: from n/a through <= 3.6.16.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The My Calendar WordPress plugin <=3.6.16 has missing authorization, allowing attacker exploitation of incorrectly configured access controls.
Vulnerability
Overview The My Calendar plugin for WordPress, versions 3.6.16 and earlier, suffers from a Missing Authorization vulnerability [1]. This issue stems from incorrectly configured access control security levels, which can lead to unauthorized actions being performed by an unauthenticated or low-privileged user.
Exploitation
Details An attacker can exploit this broken access control vulnerability by sending crafted requests that bypass the intended authorization checks [1]. No authentication or special privileges are required, as the missing authorization check allows any user to trigger functionality that should be restricted to higher-privileged roles.
Impact
Successful exploitation could allow an attacker to execute actions that are normally reserved for administrators or other privileged users, potentially leading to unauthorized modifications, data exposure, or other malicious activities within a WordPress site [1].
Mitigation
The vendor has released version 3.6.17, which addresses this vulnerability [1]. Users are strongly advised to update immediately. For sites that cannot be updated immediately, temporary mitigations (such as disabling the plugin or using a web application firewall) may reduce risk, but updating is the definitive solution [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <= 3.6.16
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.