Cross-Site Scripting in The Holiday Calendar Plugin for WordPress
CVE-2015-9270
6.1MEDIUM
What is CVE-2015-9270?
The Holiday Calendar plugin for WordPress contains a vulnerability that allows for cross-site scripting (XSS) through manipulation of the thc-month parameter. This security flaw could be exploited by an attacker to inject malicious scripts, potentially compromising the security of the affected website and its users. It is crucial for users of the plugin to update to version 1.11.3 or later to mitigate this risk.