CVE-2022-36390: WordPress Event Calendar – Calendar plugin <= 1.4.6 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
Published Sep 21, 2022
·Updated
Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
Affected Software
1 affected component
Total-Soft Event Calendar Wordpress<=1.4.6
Remediation
Information
Update to 1.4.7 or higher version.
Event History
Sep 21, 2022
CVE Published
via MITRE·07:03 PM
Data Sourced
via MITRE·07:03 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-36390?
CVE-2022-36390 is an Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar - Calendar plugin version <= 1.4.6 for WordPress.
2
How severe is CVE-2022-36390?
CVE-2022-36390 has a severity rating of medium with a CVSS score of 5.4.
3
How does CVE-2022-36390 affect WordPress?
CVE-2022-36390 affects Totalsoft Event Calendar - Calendar plugin version <= 1.4.6 for WordPress.
4
What is Cross-Site Scripting (XSS) vulnerability?
Cross-Site Scripting (XSS) vulnerability allows attackers to inject malicious scripts into web pages viewed by other users.
5
How can I fix CVE-2022-36390?
To fix CVE-2022-36390, update Totalsoft Event Calendar - Calendar plugin to a version higher than 1.4.6.