PT-2026-34285 · WordPress · Calj
Nabil Irawan
·
Published
2026-04-22
·
Updated
2026-05-01
·
CVE-2026-4117
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CalJ versions prior to 1.6
Description
The CalJ plugin for WordPress contains a missing authorization flaw. The
CalJSettingsPage class constructor processes the 'save-obtained-key' operation from POST data without verifying if the user possesses the manage options capability and without performing nonce verification. Because the calj.php bootstrap file instantiates CalJSettingsPage for any authenticated user accessing wp-admin URLs, such as 'admin-ajax.php', users with Subscriber-level access or higher can modify the API key setting and clear the Shabbat cache, allowing them to control the API integration.Recommendations
Update to a version later than 1.5.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Calj