What the vulnerability does
01Description
Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
What the vulnerability does
Insecure Direct Object References (IDOR) vulnerability in Spiffy Plugins Spiffy Calendar <= 4.9.0 at WordPress allows an attacker to edit or delete events.
Explanation of Vulnerability in Simple Terms
Spiffy Calendar version 4.9.0 and earlier contains a vulnerability that allows authenticated users with low privileges to read, modify, or disrupt calendar data. The flaw does not require user interaction and can be exploited over the network. Site administrators should update to a version newer than 4.9.0 to remediate the issue.
What an attacker can do
Read, modify, or disrupt calendar data without authorization.
Potential impact on your site
Low-privilege users can access or alter calendar information they shouldn't be able to.
Conditions required to exploit
Attacker must have a low-privilege account on the site.
Key dates
External resources