Input validation vulnerability in Event Calendar WD version 1.1.45

The Event Calendar WD plugin for WordPress is vulnerable to a type of cyber attack known as Cross-Site Scripting. If a person has the plugin installed on their site and it is a version up to and including 1.1.45, attackers could inject web scripts into the website, which will then execute in a visitor’s browser. This could allow the attacker to gain access to sensitive information. To protect against this attack, the plugin should be updated to the latest version, which includes measures to prevent this type of attack.

Detected in:

Event Calendar WD version open vulnerable versions: >= * <= 1.1.45

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.