The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes in all versions up to, and including, 3.8.3. This vulnerability allows authenticated attackers with contributor-level access to inject arbitrary web scripts, potentially leading to user session hijacking or unauthorized actions on pages that will execut [truncated]
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'mc_auth' parameter in all versions up to, and including, 3.7.8. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Unauthenticated attackers can append additional SQL queries into existing queries to extract [truncated]