CVE
CVE-2012-1835
4.3
CVSS
Description
Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to app/view/agenda-widget-form.php; (2) args, (3) title, (4) before_title, or (5) after_title parameter to app/view/agenda-widget.php; (6) button_value parameter to app/view/box_publish_button.php; or (7) msg parameter to /app/view/save_successful.php.
Attack Vector
-
Privileges Req.
-
User Interaction
-
Updated Sep 18, 2026View on NVD →
This CVE is in S4E's catalog, but no public scanner is mapped to it yet.
Monitor this CVE on your assets
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →