Known CVE
WordPress Spider Calendar <=1.4.9 - SQL Injection
WordPress Spider Calendar plugin through 1.4.9 is susceptible to SQL injection. An attacker can execute arbitrary SQL commands via the cat_id parameter in a spiderbigcalendar_month action to wp-admin/admin-ajax.php, thus making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations.
CVE-2015-2196
High2015CVSS 7.5CWE-89
time-based-sqli · cve2015 · wordpress · wp · sqli · wpscan · wp-plugin · spider-event-calendar
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website