Cross-Site Scripting in The Holiday Calendar Plugin for WordPress
CVE-2015-9270

6.1MEDIUM

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
1 October 2018

What is CVE-2015-9270?

The Holiday Calendar plugin for WordPress contains a vulnerability that allows for cross-site scripting (XSS) through manipulation of the thc-month parameter. This security flaw could be exploited by an attacker to inject malicious scripts, potentially compromising the security of the affected website and its users. It is crucial for users of the plugin to update to version 1.11.3 or later to mitigate this risk.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.