CVE-2022-2846: Calendar Event Multi View < 1.4.07 - Unauthenticated Arbitrary Event Creation to Stored XSS
The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2846?
The severity of CVE-2022-2846 is medium with a CVSS score of 4.3.
How does CVE-2022-2846 affect the Calendar Event Multi View WordPress plugin?
CVE-2022-2846 affects the Calendar Event Multi View WordPress plugin versions up to and including 1.4.07.
What can unauthenticated attackers do with CVE-2022-2846?
Unauthenticated attackers can create arbitrary events and publish them using CVE-2022-2846.
Are there any known exploits for CVE-2022-2846?
Yes, there are known exploits for CVE-2022-2846 that allow for cross-site scripting (XSS) attacks.
How can I fix CVE-2022-2846?
To fix CVE-2022-2846, upgrade to the latest version of the Calendar Event Multi View WordPress plugin (version 1.4.08 or higher) that includes authorisation, CSRF checks, and proper sanitisation and escaping of event fields.