PT-2026-67662 · WordPress · Simple Google Calendar Outlook Events Block Widget

CVE-2026-16536

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Simple Google Calendar Outlook Events Widget versions prior to 3.1.0
Description An issue exists where the plugin fails to validate a user-supplied URL before performing a server-side request. This allows unauthenticated attackers to conduct Server-Side Request Forgery (SSRF) attacks—a technique where the server is tricked into making requests to an unintended location—and potentially read the responses from internal requests via the calendar id variable.
Recommendations Update to version 3.1.0 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16536

Affected Products

Simple Google Calendar Outlook Events Block Widget