Lucene search

K
patchstackMarco WotschkaPATCHSTACK:2BADE583D8545FBBBB36929BC47A925D
HistoryNov 03, 2022 - 12:00 a.m.

WordPress VR Calendar plugin <= 2.3.3 – Cross-Site Request Forgery (CSRF) vulnerability

2022-11-0300:00:00
Marco Wotschka
patchstack.com
2
wordpress
vr calendar
cross-site request forgery
csrf
marco wotschka
deletion
modification
plugin settings
update.

0.001 Low

EPSS

Percentile

38.7%

Cross-Site Request Forgery (CSRF) vulnerability leading to deletion and modification of calendars as well as the plugin settings discovered by Marco Wotschka in the WordPress VR Calendar plugin (versions <= 2.3.3).

Solution

           Update the WordPress VR Calendar plugin to the latest available version (at least 2.3.4).
CPENameOperatorVersion
vr calendarle2.3.3

0.001 Low

EPSS

Percentile

38.7%

Related for PATCHSTACK:2BADE583D8545FBBBB36929BC47A925D