NOT FIXED: <= 3.2.5 – Cross-Site Request Forgery
-
Hoping for a fix. I love the plugin and do not want to have to remove it from a dozen or more websites.
- Plugin Name: Simple Calendar
- Current Plugin Version: 3.2.5
- Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “Simple Calendar” until a patched version is available. Get more information.(opens in new tab)
- Repository URL: https://www.ads-software.com/plugins/google-calendar-events(opens in new tab)
- Vulnerability Information: https://www.wordfence.com/threat-intel/vulnerabilities/id/1218ed3b-badc-464e-adbc-76fb4f6af008?source=plugin(opens in new tab)
- Vulnerability Severity: 4.3/10.0 (Medium)
Viewing 8 replies - 1 through 8 (of 8 total)
Viewing 8 replies - 1 through 8 (of 8 total)
- The topic ‘NOT FIXED: <= 3.2.5 – Cross-Site Request Forgery’ is closed to new replies.