CVE-2020-23762: Larsens Calendar Project Larsens Calendar
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attackers to execute arbitrary web script via the "titel" column on the "Eintrage hinzufugen" tab.
Affected products
- Larsens Calendar Project Larsens Calendar: up to and including 1.2
Published 2021-04-09. Last modified 2026-06-17.