First published: Thu Aug 25 2022(Updated: )
Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Total-soft Event Calendar | <=1.4.6 |
Update to 1.4.7 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36390 is an Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar - Calendar plugin version <= 1.4.6 for WordPress.
CVE-2022-36390 has a severity rating of medium with a CVSS score of 5.4.
CVE-2022-36390 affects Totalsoft Event Calendar - Calendar plugin version <= 1.4.6 for WordPress.
Cross-Site Scripting (XSS) vulnerability allows attackers to inject malicious scripts into web pages viewed by other users.
To fix CVE-2022-36390, update Totalsoft Event Calendar - Calendar plugin to a version higher than 1.4.6.