{"id":"CVE-2026-40308","aliases":["GHSA-2mvx-f5qm-v2ch"],"url":"https://o3.security/vulnerability/CVE-2026-40308","summary":"My Calendar: Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog","details":"My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJAX endpoint, registered for unauthenticated users, passes user-supplied arguments through parse_str() without validation, allowing injection of arbitrary parameters including a site value. On WordPress Multisite installations, this enables an unauthenticated attacker to call switch_to_blog() with an arbitrary site ID and extract calendar events from any sub-site on the network, including private or hidden events. On standard Single Site installations, switch_to_blog() does not exist, causing an uncaught PHP fatal error and crashing the worker thread, creating an unauthenticated denial of service vector. This issue has been fixed in version 3.7.7.","published":"2026-04-16T21:30:52.401Z","modified":"2026-08-07T11:51:02.753888890Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"joedolson/my-calendar","fixedVersion":"3.7.7"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/joedolson/my-calendar/releases/tag/v3.7.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40308.json"},{"type":"ADVISORY","url":"https://github.com/joedolson/my-calendar/security/advisories/GHSA-2mvx-f5qm-v2ch"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40308"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:51:02.753888890Z"}}