Conversation
support@msykes Any chance of getting these fixed? I have clients using your plugin and getting vulnerability reports. I’ll be removing it from sites but wanted to report it for the benefit of others. https://www.cve.org/CVERecord?id=CVE-2026-22351 https://www.cve.org/CVERecord?id=CVE-2026-24523 https://patchstack.com/database/Wordpress/Plugin/wp-fullcalendar/vulnerability/wordpress-wp-fullcalendar-plugin-1-6-broken-access-control-vulnerability?_s_id=cve https://patchstack.com/database/wordpress/plugin/wp-fullcalendar/vulnerability/wordpress-wp-fullcalendar-plugin-1-6-sensitive-data-exposure-vulnerability I wonder why is this plugin not patched by someone (author, plugins team, repo security bot, etc) or not taken down? There should be a patch submission process for widely used plugins needing a simple security patch. The page I need help with: [ log in to see the link]
Fundamentally the developer should fix this … but basically he does not care ! Last vulnerability took ages to be fixed and the some feeble excuse was made for not fixing earlier. Next vulnerability … even slower. Standalone use is one thing but when this is the recommended / companion for a paid plugin and it is still not fixed then even worse. Looking for an alternative for that Events plugin now as part of this issue … Would not recommend any plugin from this developer/team of Marcus and Pixelate.
Hello. Are there any updates on when this will be fixed? I have a client where this plugin is the main feature and I would really like for them not to get hacked. Does anyone have a fix I can apply manually? Thank you.
I would like to see if there is a patch we can manually apply if the author isn’t going to update it. We have a couple of sites that heavily rely on this plugin. Thank you.
Fundamentally the developer should fix this … but basically he does not care ! Last vulnerability took ages to be fixed and the some feeble excuse was made for not fixing earlier. Next vulnerability … even slower. Standalone use is one thing but when this is the recommended / companion for a paid plugin and it is still not fixed then even worse. Looking for an alternative for that Events plugin now as part of this issue … Would not recommend any plugin from this developer/team of Marcus and Pixelate.
Hello. Are there any updates on when this will be fixed? I have a client where this plugin is the main feature and I would really like for them not to get hacked. Does anyone have a fix I can apply manually? Thank you.
I would like to see if there is a patch we can manually apply if the author isn’t going to update it. We have a couple of sites that heavily rely on this plugin. Thank you.