Description
WordPress Plugin My Calendar is prone to multiple vulnerabilities, including cross-site scripting and arbitrary file override vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to steal cookie-based authentication credentials or to override arbitrary files the webserver user has access to. WordPress Plugin My Calendar version 2.3.29 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.30 or latest
References
Related Vulnerabilities
MySQL CVE-2014-6496 Vulnerability (CVE-2014-6496)
WordPress Plugin TemplatesNext ToolKit Cross-Site Scripting (3.2.7)
PHP Release of Invalid Pointer or Reference Vulnerability (CVE-2022-31625)
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Cloaking (2.2.9)
Drupal Credentials Management Errors Vulnerability (CVE-2009-2374)