cleantalk
Vulnerabilities and Security Researches

Spiffy Calendar, CVE-2024-0855

CVE, Research URL

CVE-2024-0855

Application

Spiffy Calendar

Published on
Feb 27, 2024
Research Description
The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.
Affected versions
Min -, max 4.9.9.
Status
vulnerable