The Spiffy Calendar WordPress plugin... CVE-2024-0855

- AV AC AU C I A
发布: 2024-02-27
修订: 2024-02-27

The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息