Description
WordPress Plugin Calendar is prone to multiple cross-site scripting vulnerabilities because the application fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks. WordPress Plugin Calendar versions prior to 1.2.2 are vulnerable.
Remediation
Update to plugin version 1.2.2 or latest
References
Related Vulnerabilities
ownCloud Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-1850)
Drupal Core 7.x Multiple Vulnerabilities (7.0 - 7.34)
WordPress Plugin wp-easybooking Cross-Site Scripting (1.0.3)
WordPress Plugin Video Gallery-Vimeo and YouTube Gallery Cross-Site Scripting (1.1.4)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-3454)