{"error":0,"message":null,"data":{"name":"Events Shortcodes For The Events Calendar","plugin":"template-events-calendar","link":"https:\/\/wordpress.org\/plugins\/template-events-calendar\/","latest":"1789536240","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"e4a4cd8a3113f0aea647233115142da7b22d2a99a509dba7b1023c3a826d8a13","name":"Events Shortcodes For The Events Calendar [template-events-calendar] < 1.7.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24435","name":"CVE-2021-24435","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24435","description":"[en] The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues","date":"2021-09-06"},{"id":"a88ffc42-6611-406e-8660-3af24c9cc5e8","name":"Titan Framework &lt;= 1.12.1 - Reflected Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/a88ffc42-6611-406e-8660-3af24c9cc5e8","description":"The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to  Reflected Cross-Site Scripting issues","date":"2021-08-09"},{"id":"eee08abb407d2959f403915af68b99aebde3bff7","name":"Titan Framework <= (Various Versions) - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/titan-framework-various-versions-reflected-cross-site-scripting","description":"The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues.","date":"2021-08-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"c42e3572bb5f46a236a15cdab8c055f42e596ab22f5da8b7f7a7ce03a7d978d0","name":"Events Shortcodes For The Events Calendar [template-events-calendar] < 2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8adbf5cd168b85f5372e82d4fbefe6f9f7519f16","name":"WordPress Events Shortcodes For The Events Calendar plugin <= 1.9 - Arbitrary Plugin Installation vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/template-events-calendar\/vulnerability\/wordpress-events-shortcodes-for-the-events-calendar-plugin-1-9-arbitrary-plugin-installation-vulnerability","description":"Arbitrary Plugin Installation vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Events Shortcodes For The Events Calendar plugin (versions <= 1.9).","date":"2022-04-06"}],"impact":[]},{"uuid":"da7dfd24ac635bcfe1ece6a5de5ae66ccfc5a67601e197025c369ad19366b494","name":"Events Shortcodes For The Events Calendar [template-events-calendar] < 2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bc754ac2de57f95e5cb19cd9dc05263b6160b9a4","name":"WordPress Events Shortcodes For The Events Calendar plugin <= 1.9 - Arbitrary Plugin Activation vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/template-events-calendar\/vulnerability\/wordpress-events-shortcodes-for-the-events-calendar-plugin-1-9-arbitrary-plugin-activation-vulnerability","description":"Arbitrary Plugin Activation vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress Events Shortcodes For The Events Calendar plugin (versions <= 1.9).","date":"2022-04-06"}],"impact":[]},{"uuid":"cdc6be723645ab638b0ebcd159409e4c30cd7b4d71abb7d0a6d7b6ed639390bb","name":"Events Shortcodes For The Events Calendar [template-events-calendar] < 1.7.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"fa3a911ef5d3fd9ced6a435924ba852717c55f68","name":"WordPress Events Shortcodes & Templates For The Events Calendar plugin <= 1.7.1 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/template-events-calendar\/vulnerability\/wordpress-events-shortcodes-templates-for-the-events-calendar-plugin-1-7-1-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability discovered by iohex and WPScanTeam in WordPress Events Shortcodes & Templates For The Events Calendar plugin (versions <= 1.7.1).","date":"2021-08-09"}],"impact":[]},{"uuid":"a950ac4acf4e5af4b296bc5f332d994f60cb6eb308bc49cab80410a42c847da5","name":"Events Shortcodes For The Events Calendar [template-events-calendar] < 2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b62a26a6-cea0-46a7-b577-ba8d476ec1b5","name":"Multiple Plugins from Cool Plugins - Subscriber+ Arbitrary Plugin Installation &amp; Activation","link":"https:\/\/wpscan.com\/vulnerability\/b62a26a6-cea0-46a7-b577-ba8d476ec1b5","description":"Multiple plugins from the Cool Plugins vendor are missing capability and proper CSRF check in the cool_plugins_install and cool_plugins_activate  AJAX actions, available to any authenticated users, allowing them to install and activate arbitrary plugins via an archive hosted on a remote server they control","date":null}],"impact":[]},{"uuid":"f7d2ec607106031e37ea82ea712a82c38eebb1e2e08615222a5e152360835c2d","name":"Events Shortcodes For The Events Calendar [template-events-calendar] < 2.3.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-52142","name":"CVE-2023-52142","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-52142","description":"[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cool Plugins Events Shortcodes For The Events Calendar.This issue affects Events Shortcodes For The Events Calendar: from n\/a through 2.3.1.","date":"2024-01-08"},{"id":"b5ff51588633a9c3f50c54c46d1f1bb3c9f6127d","name":"WordPress  Events Shortcodes & Templates For The Events Calendar Plugin  <= 2.3.1 is vulnerable to SQL Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/template-events-calendar\/vulnerability\/wordpress-events-shortcodes-for-the-events-calendar-plugin-2-3-1-sql-injection-vulnerability","description":"Update the WordPress Events Shortcodes & Templates For The Events Calendar plugin to the latest available version (at least 2.3.2).\nMuhammad Daffa discovered and reported this SQL Injection vulnerability in WordPress Events Shortcodes & Templates For The Events Calendar Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 2.3.2.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-28"},{"id":"3113ce776e9bc6461020ac53e276457710fb23c1","name":"Events Shortcodes & Templates For The Events Calendar <= 2.3.1 - Authenticated (Contributor+) SQL Injection via shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/template-events-calendar\/events-shortcodes-templates-for-the-events-calendar-231-authenticated-contributor-sql-injection-via-shortcode","description":"The Events Shortcodes & Templates For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 2.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2023-12-28"},{"id":"c43f860f-ca0b-4d59-a894-45b66d249318","name":"Events Shortcodes &amp; Templates For The Events Calendar &lt; 2.3.2 - Authenticated (Contributor+) SQL Injection via shortcode","link":"https:\/\/wpscan.com\/vulnerability\/c43f860f-ca0b-4d59-a894-45b66d249318","description":"The Events Shortcodes &amp; Templates For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin&#039;s shortcode in versions up to, and including, 2.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:L","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"h","i":"n","a":"l","score":"7.6","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:H\/I:N\/A:L","score":"7.6","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"high","i":"none","a":"low","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}}]},"updated":"1776153795"}