CVE-2024-11870
- EPSS 0.27%
- Veröffentlicht 15.01.2025 08:15:25
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Event Registration Calendar By vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping on user supp...
CVE-2023-2406
- EPSS 0.16%
- Veröffentlicht 03.06.2023 05:15:09
- Zuletzt bearbeitet 08.04.2026 17:16:55
The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions...
CVE-2023-2407
- EPSS 0.1%
- Veröffentlicht 03.06.2023 05:15:09
- Zuletzt bearbeitet 08.04.2026 17:16:55
The Event Registration Calendar By vcita plugin, versions up to and including 3.10.0, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validat...