Description
WordPress Plugin Calendar Event Multi View is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create/delete arbitrary events. WordPress Plugin Calendar Event Multi View version 1.4.06 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.07 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:5F191D25-833B-4D8D-A4FF-D180A326DD82
https://sploitus.com/exploit?id=WPEX-ID:95F92062-08CE-478A-A2BC-6D026ADF657C
https://plugins.svn.wordpress.org/cp-multi-view-calendar/trunk/README.txt
Related Vulnerabilities
phpBB Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-8226)
React Deserialization of Untrusted Data Vulnerability (CVE-2025-55184)
WordPress Plugin SupportCandy Arbitrary File Upload (2.0.0)
Oracle JRE CVE-2013-2473 Vulnerability (CVE-2013-2473)
WordPress Plugin Weaver Xtreme Theme Support Cross-Site Scripting (6.2.6)