plugin

Spider Event Calendar Vulnerabilities

12 known security issues reported for the Spider Event Calendar WordPress plugin. Most recent disclosed Feb 14, 2022.

2 critical 1 high 1 medium

Running Spider Event Calendar on your site? Check whether your installed version is affected.

Scan your site free

SpiderCalendar [spider-event-calendar] <= 1.5.65 (unfixed + closed)

unknown

[en] The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.

Affected:
up to 1.5.65
Fix:
No patched version reported
Disclosed:
Feb 14, 2022

CVE-2022-0212 on NVD →

SpiderCalendar <= 1.6.64 - Reflected Cross-Site Scripting

medium

The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.

CVSS:
6.1
Affected:
up to 1.5.65
Fixed in:
1.6.65
Disclosed:
Jan 13, 2022

CVE-2022-0212 on NVD →

SpiderCalendar [spider-event-calendar] < 1.5.52 (closed)

unknown

[en] SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.

Affected:
up to 1.5.52
Fixed in:
1.5.52
Disclosed:
Apr 12, 2017

CVE-2017-7719 on NVD →

SpiderCalendar <= 1.5.51 - SQL Injection

critical

SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.

CVSS:
9.8
Affected:
up to 1.5.51
Fixed in:
1.5.52
Disclosed:
Apr 10, 2017

CVE-2017-7719 on NVD →

SpiderCalendar [spider-event-calendar] < 1.5.39 (closed)

unknown

Reflected Cross-Site Scripting (XSS) Vulnerability was found in WordPress Event Calendar (Spider Event Calendar) plugin in 1.5.38 version. Update the plugin.

Affected:
up to 1.5.39
Fixed in:
1.5.39
Disclosed:
Apr 4, 2017

SpiderCalendar [spider-event-calendar] <= 1.5.65 (closed)

unknown

This plugin is prone to security bypass, cross site scripting and SQL injection vulnerabilities. Update the plugin.

Affected:
up to 1.5.65
Fixed in:
1.5.65
Disclosed:
May 15, 2015

SpiderCalendar <= 1.4.13 - Cross-Site Request Forgery

high

The SpiderCalendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.13. This is due to missing or incorrect nonce validation on the Manage_Spider_Calendar() function. This makes it possible for unauthenticated attackers to make modifications to calendars via a forge...

CVSS:
8.8
Affected:
up to 1.4.13
Fixed in:
1.4.14
Disclosed:
Mar 11, 2015

SpiderCalendar [spider-event-calendar] < 1.4.14

unknown

The SpiderCalendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.13. This is due to missing or incorrect nonce validation on the Manage_Spider_Calendar() function. This makes it possible for unauthenticated attackers to make modifications to calendars via a forge...

Affected:
up to 1.4.14
Fixed in:
1.4.14
Disclosed:
Mar 11, 2015

SpiderCalendar [spider-event-calendar] < 1.4.14

unknown

[en] SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.

Affected:
up to 1.4.14
Fixed in:
1.4.14
Disclosed:
Mar 3, 2015

CVE-2015-2196 on NVD →

SpiderCalendar <= 1.4.9 - Unauthenticated SQL Injection

critical

SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.

CVSS:
9.8
Affected:
up to 1.4.10
Fixed in:
1.4.10
Disclosed:
Feb 13, 2015

CVE-2015-2196 on NVD →

SpiderCalendar [spider-event-calendar] < 1.3.1 (closed)

unknown

Spider Event Calendar plugin is prone to multiple vulnerabilities: 1. Insufficient access check for AJAX operations in "calendar.php"; 2. SQL Injection in "calendar.php" function "spider_calendar_quick_update"; 3. SQL Injection in "calendar.php" function "spider_calendar_quick_edit"; 4. SQL Injection in "calendar_f...

Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
May 26, 2013

SpiderCalendar [spider-event-calendar] < 1.4.14

unknown

The plugin does not validate and properly escape the order_by parameter before using it in a SQL statement when searching events in the admin dashboard, leading to an SQL injection

Affected:
up to 1.4.14
Fixed in:
1.4.14

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database