CVE-2022-0212: SpiderCalendar <= 1.5.65 - Reflected Cross-Site Scripting
The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting it back in the page via the window AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0212?
CVE-2022-0212 refers to a vulnerability in the SpiderCalendar WordPress plugin version 1.5.65 that allows for a Reflected Cross-Site Scripting issue.
How severe is CVE-2022-0212?
CVE-2022-0212 has a severity level of medium with a CVSS score of 6.1.
Who is affected by CVE-2022-0212?
The SpiderCalendar WordPress plugin version 1.5.65 is affected by CVE-2022-0212.
How can I fix CVE-2022-0212?
To fix CVE-2022-0212, it is recommended to update the SpiderCalendar plugin to a version beyond 1.5.65 as soon as a patch becomes available.
Is CVE-2022-0212 a common vulnerability?
CVE-2022-0212 falls under the category of a common vulnerability known as Reflected Cross-Site Scripting (XSS).