Tag: security

My Calendar 3.4.22: Security Release

November 26, 2023

No Comments

Topics: Plugins, WordPress.

Thanks to the security researchers at Tenable.com for responsible disclosure and communication concerning this issue. Security Issue Addressed Prior versions of My Calendar 3.4 contained an unauthenticated SQL (Structured Query Language (a database standard)) injection vulnerability. Tenable.com has assessed this issue with a CVE score of 8.6. This is a severe security issue, so please update My Calendar as soon as possible. Read the published security advisory from Tenable.com. There are no changes between 3.4.21 and 3.4.22 other than this […]

Continue reading “My Calendar 3.4.22: Security Release” »

Plugin Vulnerability fixed in My Calendar 3.3.17

July 17, 2022

1 Comment

Topics: Plugins.

This morning, I was alerted to suspicious activity in server logs referring to the My Calendar print view by a concerned user. Checking the data, it was clear that there was a significant security issue in My Calendar which was being used to generate links out to remote sites by abusing the referrer URL (Uniform Resource Locator) in the My Calendar print view. This security issue was fixed in version 3.3.17, released this morning. The issue would not impact any […]

Continue reading “Plugin Vulnerability fixed in My Calendar 3.3.17” »

Important: Security Fix for My Calendar

April 20, 2015

No Comments

Topics: WordPress.

I’m releasing an update to My Calendar today as part of a coordinated security release affecting dozens of major plug-ins in the WordPress.org repository. If you’re currently running any version in the 2.3.x branch of My Calendar, your site is vulnerable. If you’re on an older version of My Calendar, you are not vulnerable to this security issue, but you may be vulnerable to a security issue I fixed in version 2.3.10. My recommendation is that all users should upgrade […]

Continue reading “Important: Security Fix for My Calendar” »

Security Update for WP to Twitter

September 12, 2014

2 Comments

Topics: WordPress.

On September 8th, the web site Vexatious Tendencies disclosed publically a security flaw in the WP to Twitter “Tweet Now” functionality, introduced in version 2.9.0. The security flaw would allow unauthenticated users to post to the administrator’s Twitter account. See WordPress plugin vulnerability dump, part 2 for more details about the vulnerability. This is a severe vulnerability, and you should update as soon as possible. If you are still running a version of WP to Twitter older than 2.9.0, you […]

Continue reading “Security Update for WP to Twitter” »

Security Fix in My Calendar

July 14, 2014

2 Comments

Topics: WordPress.

I released version 2.3.10 of My Calendar today, which fixes a major XSS security issue. Please upgrade – regardless of your current version – as soon as possible! This issue goes back quite a long ways and applies to many versions of My Calendar. And if you’re on a version of My Calendar that it doesn’t impact, you should update anyway. Seriously. Thanks to Tim Hurley for responsibly reporting this issue!

Continue reading “Security Fix in My Calendar” »