Medium 4.3 Unfixed Closed
2025-06-27≤ 2.4.7
WordPress VR Calendar Plugin <= 2.4.7 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress VR Calendar Plugin <= 2.4.7 is vulnerable to Cross Site Request Forgery (CSRF)
CVE-2024-44013
VR Calendar <= 2.3.1 - Reflected Cross-Site Scripting
VR Calendar <= 2.4.4 - Authenticated (Administrator+) Local File Inclusion
CVE-2022-3852
VR Calendar < 2.3.1 - Reflected Cross-Site Scripting
VR Calendar <= 2.3.3 - Admin+ LFI
CVE-2022-2314