Lucene search

K
wpvulndbWpvulndbWPVDB-ID:F978AF27-604E-4E43-ABB6-3B87CC9DBEF6
HistoryFeb 10, 2022 - 12:00 a.m.

Spiffy Calendar < 4.9.1 - Subscriber+ Arbitrary Event Edition/Deletion via IDOR

2022-02-1000:00:00
wpscan.com
7

0.001 Low

EPSS

Percentile

29.9%

The plugin does not check that an event belongs to the user editing/deleting it, allowing any authenticated users to delete arbitrary one via an IDOR attack

CPENameOperatorVersion
spiffy-calendarlt4.9.1

0.001 Low

EPSS

Percentile

29.9%

Related for WPVDB-ID:F978AF27-604E-4E43-ABB6-3B87CC9DBEF6