Vulnerabilities
Vulnerable Software
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.4.3 versions.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-05-22
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <= 3.3.24.1 versions.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-03-15
The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue
CVSS Score
5.4
EPSS Score
0.002
Published
2021-11-29


Contact Us

Shodan ® - All rights reserved