Medium severity6.1NVD Advisory· Published Jul 7, 2017· Updated May 13, 2026
CVE-2017-2224
CVE-2017-2224
Description
Cross-site scripting vulnerability in Event Calendar WD prior to version 1.0.94 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected products
2- cpe:2.3:a:web-dorado:event_calendar_wd:*:*:*:*:*:wordpress:*:*Range: <=1.0.93
- Web-Dorado/Event Calendar WDv5Range: prior to version 1.0.94
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.securityfocus.com/bid/99155nvdThird Party AdvisoryVDB Entry
- jvn.jp/en/jp/JVN73550134/index.htmlnvdThird Party AdvisoryVDB Entry
- plugins.trac.wordpress.org/changeset/1671891/nvdRelease NotesThird Party Advisory
- wordpress.org/plugins/event-calendar-wd/nvdThird Party Advisory
- wpvulndb.com/vulnerabilities/8859nvd
News mentions
0No linked articles in our index yet.