Cross-Site Scripting Vulnerability in MF Gig Calendar Plugin for WordPress
CVE-2012-4242

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
1 October 2012

Summary

The MF Gig Calendar plugin for WordPress, specifically version 0.9.2, contains a cross-site scripting (XSS) vulnerability. This security issue allows remote attackers to inject arbitrary web scripts or HTML through the query string when accessing the calendar page. Such exploitation may enable unauthorized access to sensitive user information or facilitate further attacks on the website. It is crucial for users of this plugin to implement recommended security practices to mitigate risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.