ZeroHour

CVE-2024-3756

PoC
CVSS 3.1
7.5 high
EPSS
<1%p25
Published
()
Modified
Description

The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors and above delete arbitrary events via a CSRF attack

Vendors
mf gig calendar project
Products
mf gig calendar
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.