CVE-2023-23813 – WordPress My Calendar Plugin <= 3.4.3 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-23813
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions. The My Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://patchstack.com/database/vulnerability/my-calendar/wordpress-my-calendar-plugin-3-4-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-47427 – WordPress My Calendar Plugin <= 3.3.24.1 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2022-47427
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions. The My Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.24.1. This is due to missing or incorrect nonce validation on several functions handling the deletion of events and locations. This makes it possible for unauthenticated attackers to remove events or locations, via forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://patchstack.com/database/vulnerability/my-calendar/wordpress-my-calendar-plugin-3-3-24-1-cross-site-request-forgery-csrf?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2021-24927 – My Calendar < 3.2.18 - Subscriber+ Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24927
The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue El plugin My Calendar de WordPress versiones anteriores a 3.2.18, no sanea y escapa del parámetro callback de la acción AJAX mc_post_lookup (disponible para cualquier usuario autenticado) antes de devolverlo a la respuesta, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://wpscan.com/vulnerability/86f3acc7-8902-4215-bd75-6105d601524e • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2019-15713 – My Calendar <= 3.1.9 - Unauthenticated Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2019-15713
The my-calendar plugin before 3.1.10 for WordPress has XSS. El plugin my-calendar versiones anteriores a 3.1.0 para WordPress, tiene una vulnerabilidad de tipo XSS. • https://wordpress.org/plugins/my-calendar/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •