NA

CVE-2024-0855

Published: 27/02/2024 Updated: 27/02/2024

Vulnerability Summary

The Spiffy Calendar WordPress plugin prior to 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.