Description
WordPress Plugin Spiffy Calendar is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently update an option. WordPress Plugin Spiffy Calendar version 4.9.10 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.9.11 or latest
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2007-1887)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1617)
Joomla CVE-2012-0836 Vulnerability (CVE-2012-0836)
WordPress Plugin WP Prayer Multiple Cross-Site Request Forgery Vulnerabilities (1.6.5)
Ruby Resource Management Errors Vulnerability (CVE-2008-3443)