Description
WordPress Plugin Spiffy Calendar is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update an option. WordPress Plugin Spiffy Calendar version 4.9.10 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.9.11 or latest
References
Related Vulnerabilities
PostgreSQL Resource Management Errors Vulnerability (CVE-2007-4772)
Ruby Improper Authentication Vulnerability (CVE-2008-3905)
Magento Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2019-8235)
WordPress 3.1 Multiple Vulnerabilities (0.7 - 3.1)
Envoy Proxy Improper Authentication Vulnerability (CVE-2021-21378)