Spiffy Calendar <= 5.0.7 - Missing Authorization
Spiffy Calendar
Minimum safe version
5.0.8
Update to 5.0.8 or later to address 21 fixable vulnerabilities
CVE-2024-45457
CVE-2024-45458
CVE-2024-43969
CVE-2024-38692
CVE-2024-30528
CVE-2024-30427
CVE-2024-0855
CVE-2023-49745
Spiffy Calendar <= 4.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2023-32122
Spiffy Calendar <= 4.9.3 - Reflected Cross-Site Scripting via page parameter
CVE-2022-46859
Spiffy Calendar <= 4.9.1 - Authenticated (Contributor+) SQL Injection
CVE-2022-29434
WordPress Spiffy Calendar plugin <= 4.9.0 - Edit/Delete event via IDOR vulnerability
WordPress Spiffy Calendar plugin <= 4.9.0 - Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities
WordPress Spiffy Calendar plugin <= 4.9.0 - Admin+ Persistent Cross-Site Scripting (XSS) vulnerability
WordPress Spiffy Calendar plugin <= 4.9.0 - Authenticated Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2017-9420
CVE-2022-25599