CVE-2023-6360 is an unauthenticated SQL injection vulnerability in the WordPress My Calendar plugin affecting versions prior to 3.4.22. The flaw is exposed through the REST API route /my-calendar/v1/events, where attacker-controlled from and to parameters are processed through the event retrieval flow and ultimately interpolated into a SQL query in my_calendar_get_events() without use of wpdb->prepare(). Although the plugin attempted to validate these date parameters via mc_checkdate(), a logic flaw allowed malicious non-date input to pass validation: mc_checkdate() used strtotime() on attacker input and, when parsing failed, still derived month/day/year values from current time via mc_date(), allowing checkdate() to succeed for invalid input. As a result, crafted SQL payloads supplied in from or to could reach the backend query. Public analysis demonstrated boolean-based, error-based, and time-based blind SQL injection against MySQL/MariaDB via this endpoint.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N indicates high confidentiality impact with no privileges or user interaction required.If you can’t patch tonight, do this now.
/my-calendar/v1/events REST route where feasible, including via WAF, reverse proxy, or application-layer access controls. Filter or block requests containing suspicious SQL metacharacters or anomalous from/to values, especially where those parameters are expected to be dates. Monitor web and database logs for requests to ?rest_route=/my-calendar/v1/events containing quote characters, boolean conditions, SLEEP(), or other SQLi indicators. These measures are temporary risk reductions only and do not replace upgrading to 3.4.22 or later.Patch, then assume compromise.
mc_checkdate() so that it returns a normalized Y-m-d date only when validation succeeds and returns false on invalid input, preventing attacker-supplied payloads from reaching the vulnerable SQL query. If maintaining a fork or custom patch set, ensure invalid from and to values are rejected before query construction and, preferably, refactor the affected SQL construction in my_calendar_get_events() to use parameterized queries such as wpdb->prepare() for all user-controlled values.No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.