CVE-2026-16536 PUBLISHED

Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_id

Assigner: WPScan
Reserved: 22.07.2026 Published: 04.08.2026 Updated: 04.08.2026

The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal request.

Product Status

Vendor Unknown
Product Simple Google Calendar Outlook Events Widget
Versions Default: unaffected
  • affected from 0 to 3.1.0 (excl.)

Credits

  • Pablo González Pérez finder
  • Francisco José Ramírez Vicente and Iñigo Sánchez Enciso finder
  • WPScan coordinator

References

Problem Types

  • CWE-918 Server-Side Request Forgery (SSRF) CWE