Larsens Calender <= 1.2 - Authenticated Stored Cross-Site Scripting
mediumCross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attackers to execute arbitrary web script via the "tite" column on the "Eintrage hinzufugen" tab.
- CVSS:
- 6.4
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 9, 2021