Record summary

CVE-2019-15713 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The my-calendar plugin before 3.1.10 for WordPress has XSS.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress My Calendar <= 3.1.9 - Cross-Site ScriptingCVSS 6.1

WordPress plugin My Calendar <= 3.1.9 is susceptible to reflected cross-site scripting which can be triggered via unescaped usage of URL parameters in multiple locations throughout the site.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, leading to potential data theft, session hijacking, or defacement.

Remediation

Update to the latest version of the My Calendar plugin (>= 3.1.10) or apply the vendor-provided patch to fix the XSS vulnerability.

WeaknessesCWE-79
Authorsdaffainfo, dhiyaneshDk
Template tagscvecve2019wordpressxsswp-pluginwpscanmy_calendar_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:my_calendar_project:my_calendar:*:*:*:*:*:wordpress:*:*
FOFA: "wordpress" && body="wp-content/plugins/my-calendar"

Source: ProjectDiscovery

References

2