CVE-2022-0600: Myceliumdesign Conference Scheduler
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
The Conference Scheduler WordPress plugin before 2.4.3 does not sanitize and escape the tab parameter before outputting back in an admin page, leading to a Reflected Cross-Site Scripting.
Affected products
- Myceliumdesign Conference Scheduler: before 2.4.3 (fixed in 2.4.3)
Published 2022-03-28. Last modified 2026-06-17.