Input validation vulnerability in Digital Events Calendar 1.0.8

The Digital Events Calendar add-on for WordPress is at risk of a type of hacking called Stored Cross-Site Scripting. This happens when the ‘column’ setting is used in versions 1.0.8 and earlier. The problem is caused by not properly cleaning up the input and output of the add-on. This means that people who are logged in and have Contributor-level privileges or higher can add harmful web scripts to pages that will run whenever someone views that page.

Detected in:

Digital Events Calendar open vulnerable versions: >= * <= 1.0.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.