Extension WordPress

Vulnérabilités Simple Calendar – Google Calendar Plugin

Cette page rassemble les failles publiées pour Simple Calendar – Google Calendar Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
0Critiques
7Avec correctif
6,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Simple Calendar – Google Calendar Plugin

7 fiches

CVE-2024-8549 Moyenne · 6,1
Simple Calendar – Google Calendar Plugin

Simple Calendar – Google Calendar Plugin <= 3.4.2 – Reflected Cross-Site Scripting

The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.2. This makes…

Versions affectées

*-3.4.2

Correctif

3.4.3

Publication

24/09/2024

CVE-2023-49151 Moyenne · 6,4
Simple Calendar – Google Calendar Plugin

Google Calendar Events <= 3.2.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user…

Versions affectées

*-3.2.7

Correctif

3.2.8

Publication

28/11/2023

CVE-2023-46189 Moyenne · 4,3
Simple Calendar – Google Calendar Plugin

Google Calendar Events <= 3.2.5 – Cross-Site Request Forgery via bulk_actions

The Google Calendar Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.5. This is due to missing nonce validation on the 'bulk_actions' function. This makes it possible for unauthenticated attackers…

Versions affectées

*-3.2.5

Correctif

3.2.6

Publication

18/10/2023

Vulnérabilité Moyenne · 4,3
Simple Calendar – Google Calendar Plugin

Simple Calendar <= 3.1.42 – Cross-Site Request Forgery to Transient Cache Clearing

The Simple Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.42. This is due to missing nonce validation on the clear_cache() function used to clear the plugin's transients. This makes…

Versions affectées

*-3.1.42

Correctif

3.1.43

Publication

11/05/2023

CVE-2014-7138 Moyenne · 6,1
Simple Calendar – Google Calendar Plugin

Simple Calendar – Google Calendar Plugin < 2.0.4 – Reflected Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in the Google Calendar Events plugin before 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gce_feed_ids parameter in a gce_ajax action to wp-admin/admin-ajax.php.

Versions affectées

[*, 2.0.4)

Correctif

2.0.4

Publication

08/10/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités