Lucene search

K
cvelistWPScanCVELIST:CVE-2024-3756
HistoryMay 06, 2024 - 6:00 a.m.

CVE-2024-3756 MF Gig Calendar <= 1.2.1 - Arbitrary Event Deletion via CSRF

2024-05-0606:00:02
WPScan
www.cve.org
7
mf gig calendar
wordpress plugin
arbitrary event deletion
csrf
contributors

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%

The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "MF Gig Calendar",
    "versions": [
      {
        "status": "affected",
        "versionType": "semver",
        "version": "0",
        "lessThanOrEqual": "1.2.1"
      }
    ],
    "defaultStatus": "affected"
  }
]

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%