CVE-2022-0600: Myceliumdesign Conference Scheduler

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting.

Affected products

Published 2022-03-28. Last modified 2026-06-17.