Access violation vulnerability in My Calendar 2.3.29

The My Calendar plugin for WordPress is vulnerable to an attack called Path Traversal. This attack affects versions up to 2.3.29 of the plugin. The attack is possible by using the ‘edit_my_calendar_styles’ function which can be found in the ‘my-calendar-styles.php’ file. Unauthenticated attackers, that is attackers who don’t have to sign-in to access the vulnerable plugin, can use this attack to overwrite the contents of all files the vulnerable plugin has access to. These attackers can even add executable PHP code to existing PHP files.

Detected in:

My Calendar fixed vulnerable versions: >= * <= 2.3.29
My Calendar – Accessible Event Manager fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.