Description
WordPress Plugin Events Widgets For Elementor And The Events Calendar is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently download and extract a remote ZIP file on the blog, which can lead to remote code execution. WordPress Plugin Events Widgets For Elementor And The Events Calendar version 1.4.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5 or latest
References
Related Vulnerabilities
WordPress Plugin Visualizer:Tables and Charts Manager for WordPress Cross-Site Scripting (3.9.1)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5665)
Oracle Database Server CVE-2006-1866 Vulnerability (CVE-2006-1866)
MySQL CVE-2021-2196 Vulnerability (CVE-2021-2196)
WordPress Plugin PayPal Digital Goods powered by Cleeng Cross-Site Scripting (2.2.13)