CSRF Vulnerability in Bg Orthodox Calendar by Vadim Bogaiskov
CVE-2025-28958
7.1HIGH
What is CVE-2025-28958?
A Cross-Site Request Forgery (CSRF) vulnerability exists in Vadim Bogaiskov's Bg Orthodox Calendar plugin, allowing attackers to perform unauthorized actions on behalf of users. This flaw can lead to Stored Cross-Site Scripting (XSS), where malicious scripts can be injected and executed in the context of users' browsers. Affected versions of the plugin include those prior to 0.13.10, making it crucial for users to update their installations to mitigate the risk of exploitation.
Affected Version(s)
Bg Orthodox Calendar <= 0.13.10