ZeroHour

CVE-2017-9420

CVSS 3.0
6.1 medium
EPSS
1%p69
Published
()
Modified
Description

Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.

Vendors
sunnythemes
Products
spiffy calendar
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.