S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 18, 2024

CVE-2023-6360 Scanner

CVE-2023-6360 scanner - SQL Injection (SQLi) vulnerability in My Calendar plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-6360
9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

The 'My Calendar' WordPress Plugin, version < 3.4.22 is affected by an unauthenticated SQL injection vulnerability in the 'from' and 'to' parameters in the '/my-calendar/v1/events' rest route.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
AFFECTED< 3.4.22SAFE ✓≥ 3.4.22
Updated Aug 22, 2026View on NVD →
Detail

Vulnerability Overview

CVE Identifier: CVE-2023-6360

Vulnerable Component: WordPress My Calendar plugin

Parameters Affected: 'from' and 'to' parameters in '/my-calendar/v1/events' REST route

Issue: Unauthenticated SQL Injection

Vulnerability Details

The vulnerability stems from a lack of proper sanitization of the 'from' and 'to' parameters within the '/my-calendar/v1/events' REST route. Attackers can exploit this oversight by crafting malicious requests that manipulate the SQL query, potentially leading to unauthorized database access, information disclosure, or database manipulation.

Possible Effects

An exploitation of this vulnerability could lead to significant impacts on an organization, including unauthorized access to sensitive data, manipulation of calendar events, and potentially compromising the entire WordPress site. It may also serve as a gateway for more sophisticated attacks against the website's users or infrastructure.

Why Choose S4E

S4E provides a user-friendly platform that simplifies the process of scanning for and understanding various vulnerabilities. By becoming a member, you gain access to a suite of tools designed to enhance your website's security posture. Our scanners are updated regularly to detect the latest vulnerabilities, ensuring your site remains protected against evolving threats. Join us to make cybersecurity accessible and manageable.

References

Solution Advice
  • Immediate Upgrade: Ensure the My Calendar plugin is updated to version 3.4.22 or later.
  • Security Review: Conduct a thorough security review of the plugin settings and WordPress installation.
  • Regular Updates: Regularly update all plugins, themes, and WordPress core to their latest versions.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.