WordPress Plugin Vulnerabilities

Spiffy Calendar < 4.9.9 - Broken Access Control

Description

The plugin doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.

Proof of Concept

Affects Plugins

Fixed in 4.9.9

References

Classification

Type
INCORRECT AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
cyc707
Submitter
cyc707
Verified
Yes

Timeline

Publicly Published
2024-01-12 (about 1 year ago)
Added
2024-02-02 (about 1 year ago)
Last Updated
2024-02-02 (about 1 year ago)

Other