WPIntell

Source evidence

Vulnerabilities still exist in v1.6

WP FullCalendar · support · 2026-04-17T21:01:00+00:00

complaintsentiment
highseverity
1.0relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

7 / 36 rows with source links

19.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Rob – 5StarPlugins / PressWizards unresolved
@msykes Any chance of getting these fixed? I have clients using your plugin and getting vulnerability reports. I’ll be removing it from sites but wanted to report it for the benefit of others. https://www.cve.org/CVERecord?id=CVE-2026-22351 https://www.cve.org/CVERecord?id=CVE-2026-24523 https://patchstack.com/database/Wordpress/Plugin/wp-fullcalendar/vulnerability/wordpress-wp-fullcalendar-plugin-1-6-broken-access-control-vulnerability?_s_id=cve https://patchstack.com/database/wordpress/plugin/wp-fullcalendar/vulnerability/wordpress-wp-fullcalendar-plugin-1-6-sensitive-data-exposure-vulnerability I wonder why is this plugin not patched by someone (author, plugins team, repo security bot, etc) or not taken down? There should be a patch submission process for widely used plugins needing a simple security patch. The page I need help with: [ log in to see the link] Fundamentally the developer should fix this … but basically he does not care ! Last vulnerability took ages to be fixed and the some feeble excuse was made for not fixing earlier. Next vulnerability … even slower. Standalone use is one thing but when this is the recommended / companion for a paid plugin and it is still not fixed then even worse. Looking for an alternative for that Events plugin now as part of this issue … Would not recommend any plugin from this developer/team of Marcus and Pixelate. Hello. Are there any updates on when this will be fixed? I have a client where this plugin is the main feature and I would really like for them not to get hacked. Does anyone have a fix I can apply manually? Thank you. I would like to see if there is a patch we can manually apply if the author isn’t going to update it. We have a couple of sites that heavily rely on this plugin. Thank you.

Comments

3 shown
tmb4016 2026-04-27T15:43:00+00:00

Fundamentally the developer should fix this … but basically he does not care ! Last vulnerability took ages to be fixed and the some feeble excuse was made for not fixing earlier. Next vulnerability … even slower. Standalone use is one thing but when this is the recommended / companion for a paid plugin and it is still not fixed then even worse. Looking for an alternative for that Events plugin now as part of this issue … Would not recommend any plugin from this developer/team of Marcus and Pixelate.

Emily 2026-05-18T17:58:00+00:00

Hello. Are there any updates on when this will be fixed? I have a client where this plugin is the main feature and I would really like for them not to get hacked. Does anyone have a fix I can apply manually? Thank you.

shrestharavee1 2026-06-03T20:56:00+00:00

I would like to see if there is a patch we can manually apply if the author isn’t going to update it. We have a couple of sites that heavily rely on this plugin. Thank you.