CP Multi View Events Calendar <= 1.4.34 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The CP Multi View Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.34 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 1.4.34
- Fix:
- No patched version reported
- Disclosed:
- Mar 17, 2026
CVE-2026-25465 on NVD →
CP Multi View Event Calendar <= 1.4.36 - Missing Authorization
low
The CP Multi View Event Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.4.36. This makes it possible for authenticated attackers, with editor-level access and above, to perform an unauthorized action.
- CVSS:
- 3.8
- Affected:
- up to 1.4.36
- Fixed in:
- 1.4.37
- Disclosed:
- Sep 22, 2025
CVE-2025-58009 on NVD →
CP Multi View Event Calendar [cp-multi-view-calendar] < 1.4.15 (closed)
unknown
[en] Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar : from n/a through 1.4.13.
- Affected:
- up to 1.4.15
- Fixed in:
- 1.4.15
- Disclosed:
- Dec 9, 2024
CVE-2023-23814 on NVD →
CP Multi View Event Calendar [cp-multi-view-calendar] < 1.4.11 (closed)
unknown
[en] Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Functionality Misuse.This issue affects CP Multi View Event Calendar: from n/a through 1.4.10.
- Affected:
- up to 1.4.11
- Fixed in:
- 1.4.11
- Disclosed:
- Jun 3, 2024
CVE-2023-28492 on NVD →
CP Multi View Event Calendar <= 1.4.10 - Missing Authentication leading to Authenticated (Subscriber+) Private Form Submission
medium
The CP Multi View Event Calendar plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cpmvec_feedback function in versions up to, and including, 1.4.10. This makes it possible for subscriber-level attackers to submit 'deactivation feedback' forms to the plugi...
- CVSS:
- 4.3
- Affected:
- up to 1.4.10
- Fixed in:
- 1.4.11
- Disclosed:
- Mar 16, 2023
CVE-2023-28492 on NVD →
CP Multi View Event Calendar <= 1.4.13 - Insufficient Authorization
low
The CP Multi View Event Calendar plugin for WordPress is vulnerable to Insufficient Authorization in versions up to, and including, 1.4.13 due to a lack of access control on the 'cp-admin-int.inc.php' page used for plugin settings. This could allow authenticated attackers with editor-level permissions or above, or any...
- CVSS:
- 3.8
- Affected:
- up to 1.4.13
- Fixed in:
- 1.4.15
- Disclosed:
- Feb 20, 2023
CVE-2023-23814 on NVD →
Calendar Event Multi View <= 1.4.06 - Missing Authorization to Stored Cross-Site Scripting
high
The Calendar Event Multi View plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on event creation and deletion in versions up to, and including, 1.4.06 . This makes it possible for unauthenticated attackers to manipulate events. Additionally, some of the event fields do not un...
- CVSS:
- 7.2
- Affected:
- up to 1.4.06
- Fixed in:
- 1.4.07
- Disclosed:
- Aug 16, 2022
CVE-2022-2846 on NVD →
CP Multi View Event Calendar [cp-multi-view-calendar] < 1.4.07 (closed)
unknown
[en] The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Sc...
- Affected:
- up to 1.4.07
- Fixed in:
- 1.4.07
- Disclosed:
- Aug 16, 2022
CVE-2022-2846 on NVD →
CP Multi View Event Calendar [cp-multi-view-calendar] < 1.4.01 (closed)
unknown
[en] The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.
- Affected:
- up to 1.4.01
- Fixed in:
- 1.4.01
- Disclosed:
- Aug 2, 2021
CVE-2021-24498 on NVD →
Calendar Event Multi View <= 1.3.99 - Reflected Cross-Site Scripting
medium
The Calendar Event Multi View for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘'start' and 'end' parameters in versions up to, and including, 1.3.99 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 1.3.99
- Fixed in:
- 1.4.01
- Disclosed:
- Jul 5, 2021
CVE-2021-24498 on NVD →
CP Multi View Event Calendar [cp-multi-view-calendar] < 1.1.8 (closed)
unknown
This WordPress CP Multi View Event Calendar plugin is prone to an SQL injection via "edit.php" and "datafeed.php". This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update the plugin.
- Affected:
- up to 1.1.8
- Fixed in:
- 1.1.8
- Disclosed:
- Jul 10, 2015
CP Multi View Event Calendar [cp-multi-view-calendar] < 1.1.5 (closed)
unknown
CP Multi View Event Calendar plugin is prone to an SQL injection vulnerability in "id" and "viewid" parameters. Also, there is a cross-site scripting vulnerability in "weekstartday" parameter.
Update the plugin.
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
- Disclosed:
- Mar 3, 2015
CP Multi View Event Calendar [cp-multi-view-calendar] < 1.0.2 (closed)
unknown
[en] SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
- Disclosed:
- Nov 4, 2014
CVE-2014-8586 on NVD →
CP Multi View Event Calendar [cp-multi-view-calendar] < 1.02 (closed)
unknown
This WordPressCP Multi View Event Calendar plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update the plugin.
- Affected:
- up to 1.02
- Fixed in:
- 1.02
- Disclosed:
- Oct 27, 2014
Calendar Event Multi View < 1.0.2 - SQL Injection
critical
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.0.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.0.2
- Fixed in:
- 1.0.2
- Disclosed:
- Oct 23, 2014
CVE-2014-8586 on NVD →
CP Multi View Event Calendar [cp-multi-view-calendar] < 1.1.8 (closed)
unknown
The Calendar Event Multi View WordPress plugin was affected by an Unauthenticated SQL Injection security vulnerability.
- Affected:
- up to 1.1.8
- Fixed in:
- 1.1.8
CP Multi View Event Calendar [cp-multi-view-calendar] < 1.1.5 (closed)
unknown
The Calendar Event Multi View WordPress plugin was affected by a SQL Injection & XSS security vulnerability.
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
CP Multi View Event Calendar [cp-multi-view-calendar] < 1.4.07 (closed)
unknown
The plugin does not have any authorisation and CSRF checks in place when deleting events which could allow unauthenticated attackers to delete arbitrary events
- Affected:
- up to 1.4.07
- Fixed in:
- 1.4.07
CP Multi View Event Calendar [cp-multi-view-calendar] <= 1.4.32 (unfixed)
unknown
- Affected:
- up to 1.4.32
- Fix:
- No patched version reported
CVE-2025-58009 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database