CVE-2022-2846

CVE-2022-2846: Calendar Event Multi View < 1.4.07 - Unauthenticated Arbitrary Event Creation to Stored XSS

Vendor Unknown
Product Calendar Event Multi View
Weakness CWE-862 · Missing authorization
Published August 16, 2022
Last update April 15, 2025

CVSS base score

What the vulnerability does

01Description

The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place when creating an event, and is also lacking sanitisation as well as escaping in some of the event fields. This could allow unauthenticated attackers to create arbitrary events and put Cross-Site Scripting payloads in it.

Key dates

02Disclosure timeline

August 16, 2022 CVE published
April 15, 2025 Record updated

Related vulnerabilities

04Related CVE