WPIntell

Source evidence

3.5.9 is vulnerable to Insecure Direct Object Reference (IDOR

Simple Calendar – Google Calendar Plugin · support · 2026-01-02T04:41:00+00:00

neutralsentiment
highseverity
0.62relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

7 / 35 rows with source links

20.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
bhautik17 unresolved
Hello Simple Calendar support team, I would like to report a security issue identified in the Simple Calendar plugin (versions <= 3.5.9). Severity: Low (CVSS 5.3) Exploited: No known exploitation at this time Fixed in: No patch available yet Please review and advise on next steps regarding remediation or patch release. Thank You This topic was modified 4 months, 3 weeks ago by bhautik17 . Hi there, Thanks for reaching out to us. About the query here, please reach out to our team here . To protect your website and the security of all our users, we kindly ask that you do not post details regarding security vulnerabilities in the public WordPress support forums. Thank you for your understanding in the meantime. Kind Regards This reply was modified 4 months, 3 weeks ago by john . closed. please communicate non-publicly or reach Plugins team via plugins @ wordpress.org

Comments

2 shown
john 2026-01-02T08:10:00+00:00

Hi there, Thanks for reaching out to us. About the query here, please reach out to our team here . To protect your website and the security of all our users, we kindly ask that you do not post details regarding security vulnerabilities in the public WordPress support forums. Thank you for your understanding in the meantime. Kind Regards This reply was modified 4 months, 3 weeks ago by john .

Yui 2026-01-02T08:31:00+00:00

closed. please communicate non-publicly or reach Plugins team via plugins @ wordpress.org