Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-1274
Disclosure Date: April 02, 2024 (last updated April 02, 2024)
The My Calendar WordPress plugin before 3.4.24 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks (depending on the permissions set by the admin)
0
Attacker Value
Unknown
CVE-2024-25916
Disclosure Date: March 15, 2024 (last updated April 01, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joseph C Dolson My Calendar allows Stored XSS.This issue affects My Calendar: from n/a through 3.4.23.
0
Attacker Value
Unknown
CVE-2023-6360
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.
0
Attacker Value
Unknown
CVE-2023-23813
Disclosure Date: May 22, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions.
0
Attacker Value
Unknown
CVE-2022-47427
Disclosure Date: March 15, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions.
0
Attacker Value
Unknown
CVE-2021-24927
Disclosure Date: November 29, 2021 (last updated February 23, 2025)
The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2019-15713
Disclosure Date: August 28, 2019 (last updated November 27, 2024)
The my-calendar plugin before 3.1.10 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2012-6527
Disclosure Date: January 31, 2013 (last updated December 27, 2023)
Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
0
Attacker Value
Unknown
CVE-2002-1626
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Directory traversal vulnerability in Mike Spice My Calendar before 1.5 allows remote attackers to write arbitrary files via .. (dot dot) sequences in a URL.
0