Scheduler Widget <= 0.1.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Event Modification
mediumThe Scheduler Widget plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.1.6. This is due to the `scheduler_widget_ajax_save_event()` function lacking proper authorization checks and ownership verification when updating events. This makes it possible for authen...
- CVSS:
- 5.4
- Affected:
- up to 0.1.6
- Fix:
- No patched version reported
- Disclosed:
- Feb 13, 2026