WordPress · My Calendar – Accessible Event Manager · CVE-2026-11896
**Name of the Vulnerable Software and Affected Versions**
My Calendar – Accessible Event Manager versions prior to 3.7.15
**Description**
An Insecure Direct Object Reference (IDOR) exists due to missing validation on a user-controlled key. Unauthenticated attackers can enumerate occurrence IDs via the `vcal` parameter to access the full iCalendar export of personal, draft, trashed, and non-public calendar events. This leads to the disclosure of sensitive metadata, including titles, descriptions, dates, locations, permalinks, and details regarding the organizer and host.
**Recommendations**
Update My Calendar – Accessible Event Manager to version 3.7.15 or later.
As a temporary mitigation, restrict access to the `vcal` parameter to prevent unauthorized event enumeration.