CVE-2024-25916 – WordPress My Calendar plugin <= 3.4.23 - Cross Site Scripting (XSS) vulnerability
https://notcve.org/view.php?id=CVE-2024-25916
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joseph C Dolson My Calendar allows Stored XSS.This issue affects My Calendar: from n/a through 3.4.23. Neutralización inadecuada de la entrada durante la vulnerabilidad de generación de páginas web ('Cross-site Scripting') en Joseph C Dolson Mi calendario permite almacenar XSS. Este problema afecta a Mi calendario: desde n/a hasta 3.4.23. The My Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.23 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with, contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://patchstack.com/database/vulnerability/my-calendar/wordpress-my-calendar-plugin-3-4-23-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2023-23813 – WordPress My Calendar Plugin <= 3.4.3 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-23813
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions. The My Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://patchstack.com/database/vulnerability/my-calendar/wordpress-my-calendar-plugin-3-4-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-47427 – WordPress My Calendar Plugin <= 3.3.24.1 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2022-47427
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions. The My Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.24.1. This is due to missing or incorrect nonce validation on several functions handling the deletion of events and locations. This makes it possible for unauthenticated attackers to remove events or locations, via forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://patchstack.com/database/vulnerability/my-calendar/wordpress-my-calendar-plugin-3-3-24-1-cross-site-request-forgery-csrf?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-36371 – My Calendar <= 3.3.16 - Open Redirect
https://notcve.org/view.php?id=CVE-2022-36371
The My Calendar plugin for WordPress is vulnerable to Open Redirection in versions up to, and including, 3.3.16. This makes it possible for unauthenticated attackers to create links that look to be part of an affected site, but will redirect to the attacker's target. This vulnerability can be utilized for malicious redirection and can also be used for phishing. • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •
CVE-2021-24927 – My Calendar < 3.2.18 - Subscriber+ Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-24927
The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue El plugin My Calendar de WordPress versiones anteriores a 3.2.18, no sanea y escapa del parámetro callback de la acción AJAX mc_post_lookup (disponible para cualquier usuario autenticado) antes de devolverlo a la respuesta, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://wpscan.com/vulnerability/86f3acc7-8902-4215-bd75-6105d601524e • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •