PT-2026-34285 · WordPress · Calj

Nabil Irawan

·

Published

2026-04-22

·

Updated

2026-05-01

·

CVE-2026-4117

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions CalJ versions prior to 1.6
Description The CalJ plugin for WordPress contains a missing authorization flaw. The CalJSettingsPage class constructor processes the 'save-obtained-key' operation from POST data without verifying if the user possesses the manage options capability and without performing nonce verification. Because the calj.php bootstrap file instantiates CalJSettingsPage for any authenticated user accessing wp-admin URLs, such as 'admin-ajax.php', users with Subscriber-level access or higher can modify the API key setting and clear the Shabbat cache, allowing them to control the API integration.
Recommendations Update to a version later than 1.5.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4117

Affected Products

Calj