CVE-2026-6854Patch

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-10); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-10: 1Mentions · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-17: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-07-10: 1Technical Details · 2026-08-17: 107-1008-17
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-101
Patch1
2026-08-171
Disclosure1
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-6854 - high 🚨 My Calendar < 3.7.9 - Unauthenticated SQL Injection > The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-6854 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE‑2026‑6854, a high‑severity unauthenticated SQL injection in the My Calendar WordPress plugin, and provides a link to a Nuclei PoC template.

    04061548
    1.3K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-6854 (CVSS 7.5) - SQL Injection in My Calendar WordPress plugin ≤3.7.8. Unauthenticated attackers can extract sensitive database info via 'mc_auth' parameter. Patch immediately! #CVE #Vulnerability #PatchNow https://t.co/1rHJibFdbM

    Post summary

    The tweet highlights a SQL Injection vulnerability in My Calendar WordPress plugin with a high severity score and urges users to apply the patch immediately.

    0000049
    71 followersView on X

Explore more