Filtered by vendor Total-soft Subscriptions
Filtered by product Event Calendar Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-8700 1 Total-soft 1 Event Calendar 2025-06-04 7.5 High
The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.
CVE-2022-38067 1 Total-soft 1 Event Calendar 2025-02-20 6.5 Medium
Unauthenticated Event Deletion vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.
CVE-2022-36390 1 Total-soft 1 Event Calendar 2025-02-20 4.1 Medium
Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar plugin <= 1.4.6 at WordPress.