VYPR
Unrated severityNVD Advisory· Published May 6, 2024· Updated Aug 1, 2024

MF Gig Calendar <= 1.2.1 - Arbitrary Event Deletion via CSRF

CVE-2024-3756

Description

The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.