Timeline Calendar [timeline-calendar] <= 1.2 (unfixed + closed)
unknown
[en] The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Aug 23, 2021
CVE-2021-24553 on NVD →
Timeline Calendar <= 1.2 - Authenticated (Admin+) SQL Injection
high
The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before using it in a SQL statement when editing events, leading to an authenticated SQL injection issue. Other SQL Injections are also present in the plugin
- CVSS:
- 7.2
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Jul 24, 2021
CVE-2021-24553 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database