CVE-2024-0855
27.02.2024, 09:15
The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.Enginsight
Vendor | Product | Version |
---|---|---|
spiffyplugins | spiffy_calendar | 𝑥 < 4.4.9 |
spiffyplugins | spiffy_calendar | 𝑥 < 4.9.9 |
𝑥
= Vulnerable software versions