Description
Cross-Site Request Forgery (CSRF) vulnerability in George Sexton WordPress Events Calendar Plugin – connectDaily connect-daily-web-calendar allows Cross-Site Scripting (XSS).This issue affects WordPress Events Calendar Plugin – connectDaily: from n/a through <= 1.5.4.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Any version
Credits
Dhabaleshwar Das | Patchstack Bug Bounty Program
References
patchstack.com/...oss-site-scripting-vulnerability?_s_id=cve