WordPress Plugin Vulnerabilities

My Calendar <= 2.3.29 - Arbitrary File Override & Reflected XSS

Description

The file override vulnerability allows an admin to override any file on the web server, ignoring settings such as DISALLOW_FILE_EDIT.

Proof of Concept

Affects Plugins

Fixed in 2.3.30

References

Miscellaneous

Submitter
Tim Coen
Verified
No

Timeline

Publicly Published
2015-05-15 (about 10 years ago)
Added
2015-05-15 (about 10 years ago)
Last Updated
2019-10-21 (about 6 years ago)

Other