4.3
CVSSv2

CVE-2012-4242

Published: 01/10/2012 Updated: 03/08/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the MF Gig Calendar plugin 0.9.2 for WordPress allows remote malicious users to inject arbitrary web script or HTML via the query string to the calendar page.

Vulnerable Product Search on Vulmon Subscribe to Product

mf_gig_calendar_project mf_gig_calendar 0.9.2

Exploits

source: wwwsecurityfocuscom/bid/55622/info The MF Gig Calendar plugin for WordPress is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site Th ...
WordPress MF Gig Calendar plugin version 092 suffers from a cross site scripting vulnerability ...