PT-2023-10012 · WordPress · Editorial Calendar Plugin

Published

2023-04-08

·

Updated

2024-05-17

·

CVE-2013-10023

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Editorial Calendar Plugin versions up to 2.6
Description A critical issue has been found in the Editorial Calendar Plugin, affecting the function edcal filter where of the file edcal.php. The manipulation of the arguments edcal startDate and edcal endDate leads to SQL injection. This issue can be exploited remotely. Upgrading to version 2.7 addresses this issue.
Recommendations For Editorial Calendar Plugin versions up to 2.6, upgrade to version 2.7 to resolve the issue. As a temporary workaround, consider restricting the use of the edcal filter where function in the edcal.php file until the upgrade is applied.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2013-10023

Affected Products

Editorial Calendar Plugin