Description
WordPress Plugin Event Single Page Templates Addon For The Events Calendar is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently download and extract a remote ZIP file on the blog, which can lead to remote code execution. WordPress Plugin Event Single Page Templates Addon For The Events Calendar version 1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6 or latest
References
Related Vulnerabilities
WordPress Plugin Gettext override translations Cross-Site Scripting (1.0.1)
WordPress Plugin Realteo Multiple Vulnerabilities (1.2.3)
phpMyFAQ Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2023-4006)
WordPress Plugin WP eCommerce 'cart_messages[]' Parameter Cross-Site Scripting (3.8.6)
WordPress Plugin Booking Calendar Contact Form Multiple Vulnerabilities (1.0.23)