plugin

Event Calendar Wd Vulnerabilities

15 known security issues reported for the Event Calendar Wd WordPress plugin. Most recent disclosed Jan 17, 2022.

1 high 5 medium

Running Event Calendar Wd on your site? Check whether your installed version is affected.

Scan your site free

EventCalendar [event-calendar-wd] < 1.1.51 (closed)

unknown

[en] The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues

Affected:
up to 1.1.51
Fixed in:
1.1.51
Disclosed:
Jan 17, 2022

CVE-2021-25024 on NVD →

EventCalendar [event-calendar-wd] < 1.1.51 (closed)

unknown

[en] The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events

Affected:
up to 1.1.51
Fixed in:
1.1.51
Disclosed:
Jan 17, 2022

CVE-2021-25025 on NVD →

Event Calendar <= 1.1.50 - Reflected Cross-Site Scripting

medium

The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues

CVSS:
6.1
Affected:
up to 1.1.50
Fixed in:
1.1.51
Disclosed:
Dec 20, 2021

CVE-2021-25024 on NVD →

Event Calendar <= 1.1.50 - Subscriber+ Event Creation

medium

The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events

CVSS:
4.3
Affected:
up to 1.1.50
Fixed in:
1.1.51
Disclosed:
Dec 20, 2021

CVE-2021-25025 on NVD →

EventCalendar <= 1.1.45 - Cross-Site Scripting

medium

The Event Calendar WD plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.45 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
4.7
Affected:
up to 1.1.45
Fixed in:
1.1.46
Disclosed:
Jun 25, 2021

EventCalendar [event-calendar-wd] < 1.1.46 (closed)

unknown

The Event Calendar WD plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.45 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 1.1.46
Fixed in:
1.1.46
Disclosed:
Jun 25, 2021

Event Calendar <= 1.1.44 - Cross-Site Scripting

high

The Event Calendar WD plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.44 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS:
7.2
Affected:
up to 1.1.45
Fixed in:
1.1.45
Disclosed:
May 31, 2021

EventCalendar [event-calendar-wd] < 1.1.45 (closed)

unknown

Cross-Site Scripting (XSS) vulnerability discovered in WordPress Event Calendar WD plugin (versions <= 1.1.44).

Affected:
up to 1.1.45
Fixed in:
1.1.45
Disclosed:
May 31, 2021

EventCalendar [event-calendar-wd] < 1.1.45 (closed)

unknown

The Event Calendar WD plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.44 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected:
up to 1.1.45
Fixed in:
1.1.45
Disclosed:
May 31, 2021

EventCalendar [event-calendar-wd] < 1.1.22 (closed)

unknown

[en] Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 1.1.22
Fixed in:
1.1.22
Disclosed:
Jan 9, 2019

CVE-2018-16164 on NVD →

EventCalendar <= 1.1.21 - Cross-Site Scripting

medium

Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
5.4
Affected:
up to 1.1.21
Fixed in:
1.1.22
Disclosed:
Nov 2, 2018

CVE-2018-16164 on NVD →

EventCalendar [event-calendar-wd] < 1.0.94 (closed)

unknown

[en] Cross-site scripting vulnerability in Event Calendar WD prior to version 1.0.94 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 1.0.94
Fixed in:
1.0.94
Disclosed:
Jul 7, 2017

CVE-2017-2224 on NVD →

EventCalendar < 1.0.94 - Authenticated Cross-Site Scripting

medium

The EventCalendar plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.0.94 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.4
Affected:
up to 1.0.94
Fixed in:
1.0.94
Disclosed:
Jun 20, 2017

CVE-2017-2224 on NVD →

EventCalendar [event-calendar-wd] < 1.1.46 (closed)

unknown

The plugin was affected by a Cross-Site Scripting issue

Affected:
up to 1.1.46
Fixed in:
1.1.46

EventCalendar [event-calendar-wd] < 1.1.45 (closed)

unknown

The Event Calendar WD WordPress plugin fixed a Cross-Site Scripting (XSS) security vulnerability within the calendar display code and date.

Affected:
up to 1.1.45
Fixed in:
1.1.45

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database