Security Advisory

CVE-2021-25025

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-01-17 00:00:00
Last updated 2024-08-03 19:49:14
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events