HomeDefault status
affected
Any version
affected
Description
The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.
Problem types
Product status
Any version
Credits
Bob Matyas
WPScan
References
wpscan.com/...rability/8c48b657-afa1-45e6-ada6-27ee58185143/
wpscan.com/...rability/8c48b657-afa1-45e6-ada6-27ee58185143/