EventCalendar [event-calendar-wd] < 1.1.51 (closed)
unknown
[en] The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues
- Affected:
- up to 1.1.51
- Fixed in:
- 1.1.51
- Disclosed:
- Jan 17, 2022
CVE-2021-25024 on NVD →
EventCalendar [event-calendar-wd] < 1.1.51 (closed)
unknown
[en] The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events
- Affected:
- up to 1.1.51
- Fixed in:
- 1.1.51
- Disclosed:
- Jan 17, 2022
CVE-2021-25025 on NVD →
Event Calendar <= 1.1.50 - Reflected Cross-Site Scripting
medium
The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues
- CVSS:
- 6.1
- Affected:
- up to 1.1.50
- Fixed in:
- 1.1.51
- Disclosed:
- Dec 20, 2021
CVE-2021-25024 on NVD →
Event Calendar <= 1.1.50 - Subscriber+ Event Creation
medium
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events
- CVSS:
- 4.3
- Affected:
- up to 1.1.50
- Fixed in:
- 1.1.51
- Disclosed:
- Dec 20, 2021
CVE-2021-25025 on NVD →
EventCalendar <= 1.1.45 - Cross-Site Scripting
medium
The Event Calendar WD plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.45 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 4.7
- Affected:
- up to 1.1.45
- Fixed in:
- 1.1.46
- Disclosed:
- Jun 25, 2021
EventCalendar [event-calendar-wd] < 1.1.46 (closed)
unknown
The Event Calendar WD plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.45 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 1.1.46
- Fixed in:
- 1.1.46
- Disclosed:
- Jun 25, 2021
Event Calendar <= 1.1.44 - Cross-Site Scripting
high
The Event Calendar WD plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.44 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- CVSS:
- 7.2
- Affected:
- up to 1.1.45
- Fixed in:
- 1.1.45
- Disclosed:
- May 31, 2021
EventCalendar [event-calendar-wd] < 1.1.45 (closed)
unknown
Cross-Site Scripting (XSS) vulnerability discovered in WordPress Event Calendar WD plugin (versions <= 1.1.44).
- Affected:
- up to 1.1.45
- Fixed in:
- 1.1.45
- Disclosed:
- May 31, 2021
EventCalendar [event-calendar-wd] < 1.1.45 (closed)
unknown
The Event Calendar WD plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.44 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected:
- up to 1.1.45
- Fixed in:
- 1.1.45
- Disclosed:
- May 31, 2021
EventCalendar [event-calendar-wd] < 1.1.22 (closed)
unknown
[en] Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 1.1.22
- Fixed in:
- 1.1.22
- Disclosed:
- Jan 9, 2019
CVE-2018-16164 on NVD →
EventCalendar <= 1.1.21 - Cross-Site Scripting
medium
Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 5.4
- Affected:
- up to 1.1.21
- Fixed in:
- 1.1.22
- Disclosed:
- Nov 2, 2018
CVE-2018-16164 on NVD →
EventCalendar [event-calendar-wd] < 1.0.94 (closed)
unknown
[en] Cross-site scripting vulnerability in Event Calendar WD prior to version 1.0.94 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 1.0.94
- Fixed in:
- 1.0.94
- Disclosed:
- Jul 7, 2017
CVE-2017-2224 on NVD →
EventCalendar < 1.0.94 - Authenticated Cross-Site Scripting
medium
The EventCalendar plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.0.94 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.4
- Affected:
- up to 1.0.94
- Fixed in:
- 1.0.94
- Disclosed:
- Jun 20, 2017
CVE-2017-2224 on NVD →
EventCalendar [event-calendar-wd] < 1.1.46 (closed)
unknown
The plugin was affected by a Cross-Site Scripting issue
- Affected:
- up to 1.1.46
- Fixed in:
- 1.1.46
EventCalendar [event-calendar-wd] < 1.1.45 (closed)
unknown
The Event Calendar WD WordPress plugin fixed a Cross-Site Scripting (XSS) security vulnerability within the calendar display code and date.
- Affected:
- up to 1.1.45
- Fixed in:
- 1.1.45
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database