Input validation vulnerability in Appointment Calendar 2.7.4

The Appointment Calendar plugin for WordPress is known to be vulnerable to a type of attack called Multiple Reflected Cross-Site Scripting. This means that if a user can be tricked into clicking a link, attackers can inject malicious code into the page the user is visiting. This vulnerability affects all versions up to and including version 2.7.4, as the plugin does not properly protect against malicious code being inserted.

Detected in:

Appointment Calendar open vulnerable versions: >= * <= 2.7.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.