← Back to browse · API

CVE-2023-6360

Severity
HIGH
CVSS
8.6
EPSS
0.63141
Risk score
56.5
CISA KEV
No
PoC
No
Published
2023-11-30
Modified
2024-10-10
First seen
2026-08-07
Aliases
EUVD-2023-58601, GHSA-X23Q-F896-MVPF
Products
-
Sources
euvd EUVD-2023-58601

Description

The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.

References