Input validation vulnerability in Dan's Embedder for Google Calendar 1.2

The Dan’s Embedder for Google Calendar plugin for WordPress has a security flaw that makes it possible for attackers with contributor-level access and above to inject malicious web scripts into pages. This could cause the malicious web script to run every time someone visits the page, allowing the attacker to access sensitive information or take control of the page. To make sure this doesn’t happen, users should update the plugin to the latest version and always be sure to give trusted users the correct access level.

Detected in:

Dan's Embedder for Google Calendar fixed vulnerable versions: >= * <= 1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.