Beta

Report

WordPress Event Calendar (Spider Event Calendar) <= 1.5.65 is vulnerable to Reflected Cross-Site Scripting (XSS) vulnerability

Unauthenticated
Published
2022-02-12

The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.

CVSS

Score:4.7

Severity:Medium

Version: 1.5.65

The plugin vendor has not patched this vulnerability at the moment.