PT-2024-15868 · WordPress · Spiffy Calendar

Cyc707

·

Published

2024-02-27

·

Updated

2024-08-08

·

CVE-2024-0855

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Spiffy Calendar WordPress plugin versions prior to 4.9.9
Description The issue allows any user to alter the event author parameter when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.
Recommendations For versions prior to 4.9.9, update to version 4.9.9 or later to resolve the issue. As a temporary workaround, consider restricting access to event creation to trusted users only until the update is applied.

Exploit

Fix

Related Identifiers

CVE-2024-0855

Affected Products

Spiffy Calendar