PT-2023-10012 · WordPress · Editorial Calendar Plugin
Published
2023-04-08
·
Updated
2024-05-17
·
CVE-2013-10023
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Editorial Calendar Plugin versions up to 2.6
Description
A critical issue has been found in the Editorial Calendar Plugin, affecting the function
edcal filter where of the file edcal.php. The manipulation of the arguments edcal startDate and edcal endDate leads to SQL injection. This issue can be exploited remotely. Upgrading to version 2.7 addresses this issue.Recommendations
For Editorial Calendar Plugin versions up to 2.6, upgrade to version 2.7 to resolve the issue. As a temporary workaround, consider restricting the use of the
edcal filter where function in the edcal.php file until the upgrade is applied.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Editorial Calendar Plugin