Input validation vulnerability in XO Event Calendar 2.3.6

The XO Event Calendar plugin for WordPress is vulnerable to a security issue called Reflected Cross-Site Scripting (XSS). This issue could allow attackers to inject malicious web scripts into pages on a website. If a user clicks on a link that is sent to them, these malicious scripts could be executed. This vulnerability affects versions of XO Event Calendar up to and including 2.3.6. To protect against this issue, make sure you are using the latest version of the plugin and that input sanitization and output escaping is enabled.

Detected in:

XO Event Calendar fixed vulnerable versions: >= * <= 2.3.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.