Vulnerabilities > Joedolson > MY Calendar

DATE CVE VULNERABILITY TITLE RISK
2023-11-30 CVE-2023-6360 SQL Injection vulnerability in Joedolson MY Calendar
The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.
network
low complexity
joedolson CWE-89
critical
9.8