CVE: - CVE-2026-1310 CVSS: - Severity: 5.3 (Medium) - Vector: - Type: Missing Authorization Timeline: - Publicly Published: January 27, 2026 - Last Updated: January 28, 2026 Affected Plugin: - Name: Simple calendar for Elementor - Affected Versions: <= 1.6.6 - Patched Version: 1.6.7 Remediation: - Update to version 1.6.7 or a newer patched version Description: - This vulnerability allows unauthenticated attackers to delete arbitrary calendar entries by sending a request with a valid nonce and the calendar entry ID due to missing capability checks on the 'miga_ajax_editor_cal_delete' function. References: - plugins.trac.wordpress.org