CVE-2025-14160

Published
View on NVD ↗
CVSS v3
4.3
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Upcoming for Calendly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's Calendly API key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

<p>Upcoming Events Registration List for Calendly</p> <p>This WordPress plugin adds a shortcode to list upcoming scheduled events from Calendly using the Calendly API and offers registration links for already-scheduled group events that still have open slots. You can either list all of your scheduled events, or restrict it to a specific event type.</p> <p>To set it up, you will need to log into Calendly and generate an Access Token. A link to do so is provided on the settings page. Paste the token into the box on the settings page.</p> <p>To use it, place the shortcode <code>[upcoming-for-calendly]</code> on a post or page where you want the list to appear. To restrict it to a specific event type, use <code>[upcoming-for-calendly event="Event Type Name"]</code>.</p> <p>The plugin currently implements a feature I needed. I am open to adding additional features that can be implemented via Calendly&#8217;s API if there is a need for them.</p> <p>Bug reports and feature requests can be filed at the <a href="https://github.com/justdave/upcoming-for-calendly/issues" rel="nofollow ugc">GitHub repository</a>.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
2.3K