The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin)
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 May 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joedolson
Joedolson my Calendar |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:joedolson:my_calendar:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Joedolson
Joedolson my Calendar |
Tue, 27 Aug 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-27T15:28:12.101Z
Reserved: 2024-02-06T13:32:32.160Z
Link: CVE-2024-1274
Updated: 2024-08-01T18:33:25.374Z
Status : Analyzed
Published: 2024-04-02T06:15:12.050
Modified: 2025-05-07T00:29:08.973
Link: CVE-2024-1274
No data.
OpenCVE Enrichment
No data.
Weaknesses