Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-3756


The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack


Published

2024-05-06T06:15:07.197

Last Modified

2025-04-18T12:54:00.033

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mf_gig_calendar_project mf_gig_calendar ≤ 1.2.1 Yes

References