Input validation vulnerability in Events Calendar Made Simple – Pie Calendar 1.2.5

The Pie Calendar plugin for WordPress, known as The Events Calendar Made Simple, has a vulnerability that allows hackers to insert harmful code on web pages. This can happen on any version of the plugin, including the latest one (1.2.5). The issue is caused by not properly filtering and securing user input, meaning that attackers with contributor-level access or higher can add their own web scripts to pages. This can be dangerous for users who visit these pages.

Detected in:

Events Calendar Made Simple – Pie Calendar fixed vulnerable versions: >= * <= 1.2.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.