cleantalk
Vulnerabilities and Security Researches

My Calendar, 1886eb1db8aa9adf0a53533cf1f66b0bec8f6bc4

Application

My Calendar

Published on
Jan 03, 2023
Research Description
My Calendar &#8211; Accessible Event Manager [my-calendar] < 3.3.25 My Calendar <= 3.3.24.1 - Cross-Site Request Forgery The My Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.24.1. This is due to missing or incorrect nonce validation on several functions handling the deletion of events and locations. This makes it possible for unauthenticated attackers to remove events or locations, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 3.3.25.
Status
vulnerable