CVE-2022-4320

CVE-2022-4320: WordPress Events Calendar Plugin < 1.4.5 - Multiple Reflected XSS

Vendor Unknown
Product WordPress Events Calendar Plugin
Published January 16, 2023
Last update April 4, 2025

CVSS base score

What the vulnerability does

01Description

The WordPress Events Calendar WordPress plugin before 1.4.5 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high-privilege ones like admin).

Key dates

02Disclosure timeline

January 16, 2023 CVE published
April 4, 2025 Record updated