Input validation vulnerability in My Calendar 3.4.21

The My Calendar plugin for WordPress is a plugin that has a security vulnerability that could allow unauthenticated attackers to access sensitive information from the database. This vulnerability exists in all versions of the plugin up until 3.4.21. It occurs because the plugin doesn’t properly escape user supplied parameters and doesn’t properly prepare existing SQL queries. This means that attackers can add additional SQL queries to existing queries, which can then be used to access the sensitive information.

Detected in:

My Calendar fixed vulnerable versions: >= * <= 3.4.21
My Calendar – Accessible Event Manager fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.