CVE-2021-25025: Event Calendar < 1.1.51 - Subscriber+ Event Creation
Published Jan 17, 2022
·Updated
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the addcalendarevent AJAX actions, allowing users with a role as low as subscriber to create events
Affected Software
1 affected component
Theeventscalendar Eventcalendar Wordpress<1.1.51
Event History
Jan 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25025?
CVE-2021-25025 has a severity rating of medium due to improper authorization and CSRF vulnerabilities.
2
How do I fix CVE-2021-25025?
To fix CVE-2021-25025, update the EventCalendar WordPress plugin to version 1.1.51 or later.
3
What versions of the EventCalendar plugin are affected by CVE-2021-25025?
CVE-2021-25025 affects EventCalendar versions prior to 1.1.51.
4
Can subscribers exploit CVE-2021-25025?
Yes, users with as low as subscriber roles can exploit CVE-2021-25025 to create unauthorized calendar events.
5
What type of vulnerability is CVE-2021-25025?
CVE-2021-25025 is a vulnerability related to improper authorization and cross-site request forgery (CSRF) in a WordPress plugin.