plugin

All In One Event Calendar Vulnerabilities

15 known security issues reported for the All In One Event Calendar WordPress plugin. Most recent disclosed May 6, 2019.

1 critical 2 high 1 medium

Running All In One Event Calendar on your site? Check whether your installed version is affected.

Scan your site free

Timely All-in-One Events Calendar [all-in-one-event-calendar] < 2.5.39

unknown

Cross-Site Scripting (XSS) vulnerability found in WordPress All-in-One Event Calendar plugin (versions <= 2.5.38).

Affected:
up to 2.5.39
Fixed in:
2.5.39
Disclosed:
May 6, 2019

Timely All-in-One Events Calendar <= 2.5.38 - Cross-Site Scripting

medium

The Timely All-in-One Events Calendar plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters related to event input in versions up to, and including, 2.5.38 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that ex...

CVSS:
6.4
Affected:
up to 2.5.38
Fixed in:
2.5.39
Disclosed:
May 4, 2019

Timely All-in-One Events Calendar [all-in-one-event-calendar] < 2.5.39

unknown

The Timely All-in-One Events Calendar plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters related to event input in versions up to, and including, 2.5.38 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that ex...

Affected:
up to 2.5.39
Fixed in:
2.5.39
Disclosed:
May 4, 2019

Timely All-in-One Events Calendar [all-in-one-event-calendar] < 1.10

unknown

This plugin is prone to a cross site scripting vulnerability in wp-admin/post-new.php multiple parameter. Update the plugin.

Affected:
up to 1.10
Fixed in:
1.10
Disclosed:
May 15, 2015

Timely All-in-One Events Calendar [all-in-one-event-calendar] < 1.10

unknown

This plugin is prone to index.php multiple parameter SQL injection vulnerability. Update the plugin.

Affected:
up to 1.10
Fixed in:
1.10
Disclosed:
May 15, 2015

Timely All-in-One Events Calendar < 1.10 - Cross-Site Scripting

high

The Timely All-in-One Events Calendar plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.10 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.1
Affected:
up to 1.10
Fixed in:
1.10
Disclosed:
Nov 14, 2013

Timely All-in-One Events Calendar [all-in-one-event-calendar] < 1.10

unknown

The Timely All-in-One Events Calendar plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions before 1.10 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.10
Fixed in:
1.10
Disclosed:
Nov 14, 2013

All-in-One Events Calendar < 1.10 - SQL Injection

critical

The All-in-One Events Calendar plugin for WordPress is vulnerable to SQL Injection via the “ai1ec_cat_ids”, “ai1ec_post_ids” and “ai1ec_tag_ids” parameters in versions up to, and including, 1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

CVSS:
10
Affected:
up to 1.10
Fixed in:
1.10
Disclosed:
Mar 7, 2013

Timely All-in-One Events Calendar [all-in-one-event-calendar] < 1.10

unknown

The All-in-One Events Calendar plugin for WordPress is vulnerable to SQL Injection via the “ai1ec_cat_ids”, “ai1ec_post_ids” and “ai1ec_tag_ids” parameters in versions up to, and including, 1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...

Affected:
up to 1.10
Fixed in:
1.10
Disclosed:
Mar 7, 2013

Timely All-in-One Events Calendar [all-in-one-event-calendar] < 1.8.2

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to app/view/agenda-widget-form.php; (2) args, (3) title, (4) before_title, or (5) after_title parameter to...

Affected:
up to 1.8.2
Fixed in:
1.8.2
Disclosed:
Aug 14, 2012

CVE-2012-1835 on NVD →

Timely All-in-One Events Calendar < 1.6 - Cross-Site Scripting

high

Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to app/view/agenda-widget-form.php; (2) args, (3) title, (4) before_title, or (5) after_title parameter to app/v...

CVSS:
7.1
Affected:
up to 1.6
Fixed in:
1.6
Disclosed:
Apr 11, 2012

CVE-2012-1835 on NVD →

Timely All-in-One Events Calendar [all-in-one-event-calendar] < 1.5

unknown

WordPress All-in-One Event Calendar plugin's/wp-content/plugins/all-in-one-event-calendar/app/view/box_publish_button.php "button_value" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an u...

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Apr 11, 2012

Timely All-in-One Events Calendar [all-in-one-event-calendar] < 2.5.39

unknown

The All-in-One Event Calendar WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.5.39
Fixed in:
2.5.39

Timely All-in-One Events Calendar [all-in-one-event-calendar] < 1.10

unknown

The All-in-One Event Calendar WordPress plugin was affected by an index.php Multiple Parameter SQL Injection security vulnerability.

Affected:
up to 1.10
Fixed in:
1.10

Timely All-in-One Events Calendar [all-in-one-event-calendar] < 1.10

unknown

The All-in-One Event Calendar WordPress plugin was affected by a wp-admin/post-new.php Multiple Parameter XSS security vulnerability.

Affected:
up to 1.10
Fixed in:
1.10

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database