SpiderCalendar [spider-event-calendar] <= 1.5.65 (unfixed + closed)
unknown
[en] The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.
- Affected:
- up to 1.5.65
- Fix:
- No patched version reported
- Disclosed:
- Feb 14, 2022
CVE-2022-0212 on NVD →
SpiderCalendar <= 1.6.64 - Reflected Cross-Site Scripting
medium
The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.
- CVSS:
- 6.1
- Affected:
- up to 1.5.65
- Fixed in:
- 1.6.65
- Disclosed:
- Jan 13, 2022
CVE-2022-0212 on NVD →
SpiderCalendar [spider-event-calendar] < 1.5.52 (closed)
unknown
[en] SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.
- Affected:
- up to 1.5.52
- Fixed in:
- 1.5.52
- Disclosed:
- Apr 12, 2017
CVE-2017-7719 on NVD →
SpiderCalendar <= 1.5.51 - SQL Injection
critical
SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.
- CVSS:
- 9.8
- Affected:
- up to 1.5.51
- Fixed in:
- 1.5.52
- Disclosed:
- Apr 10, 2017
CVE-2017-7719 on NVD →
SpiderCalendar [spider-event-calendar] < 1.5.39 (closed)
unknown
Reflected Cross-Site Scripting (XSS) Vulnerability was found in WordPress Event Calendar (Spider Event Calendar) plugin in 1.5.38 version.
Update the plugin.
- Affected:
- up to 1.5.39
- Fixed in:
- 1.5.39
- Disclosed:
- Apr 4, 2017
SpiderCalendar [spider-event-calendar] <= 1.5.65 (closed)
unknown
This plugin is prone to security bypass, cross site scripting and SQL injection vulnerabilities.
Update the plugin.
- Affected:
- up to 1.5.65
- Fixed in:
- 1.5.65
- Disclosed:
- May 15, 2015
SpiderCalendar <= 1.4.13 - Cross-Site Request Forgery
high
The SpiderCalendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.13. This is due to missing or incorrect nonce validation on the Manage_Spider_Calendar() function. This makes it possible for unauthenticated attackers to make modifications to calendars via a forge...
- CVSS:
- 8.8
- Affected:
- up to 1.4.13
- Fixed in:
- 1.4.14
- Disclosed:
- Mar 11, 2015
SpiderCalendar [spider-event-calendar] < 1.4.14
unknown
The SpiderCalendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.13. This is due to missing or incorrect nonce validation on the Manage_Spider_Calendar() function. This makes it possible for unauthenticated attackers to make modifications to calendars via a forge...
- Affected:
- up to 1.4.14
- Fixed in:
- 1.4.14
- Disclosed:
- Mar 11, 2015
SpiderCalendar [spider-event-calendar] < 1.4.14
unknown
[en] SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.
- Affected:
- up to 1.4.14
- Fixed in:
- 1.4.14
- Disclosed:
- Mar 3, 2015
CVE-2015-2196 on NVD →
SpiderCalendar <= 1.4.9 - Unauthenticated SQL Injection
critical
SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php.
- CVSS:
- 9.8
- Affected:
- up to 1.4.10
- Fixed in:
- 1.4.10
- Disclosed:
- Feb 13, 2015
CVE-2015-2196 on NVD →
SpiderCalendar [spider-event-calendar] < 1.3.1 (closed)
unknown
Spider Event Calendar plugin is prone to multiple vulnerabilities:
1. Insufficient access check for AJAX operations in "calendar.php";
2. SQL Injection in "calendar.php" function "spider_calendar_quick_update";
3. SQL Injection in "calendar.php" function "spider_calendar_quick_edit";
4. SQL Injection in "calendar_f...
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- May 26, 2013
SpiderCalendar [spider-event-calendar] < 1.4.14
unknown
The plugin does not validate and properly escape the order_by parameter before using it in a SQL statement when searching events in the admin dashboard, leading to an SQL injection
- Affected:
- up to 1.4.14
- Fixed in:
- 1.4.14
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database