PT-2024-15868 · WordPress · Spiffy Calendar
Cyc707
·
Published
2024-02-27
·
Updated
2024-08-08
·
CVE-2024-0855
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Spiffy Calendar WordPress plugin versions prior to 4.9.9
Description
The issue allows any user to alter the
event author parameter when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.Recommendations
For versions prior to 4.9.9, update to version 4.9.9 or later to resolve the issue. As a temporary workaround, consider restricting access to event creation to trusted users only until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Spiffy Calendar