[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBparQNAQErn3EJ1D8KKVt6M11XjUg5IsHHVGyw1DrOI":3,"$fw68hEBYjcT-0zB6uZFAKSboxGunRUB7Z2_3hjbhq_4Q":384,"$fayPQ2VmOeI5GqoGU23ARci2o8G73uUZsRkVJ0gmqKcw":389},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"discovery_status":31,"vulnerabilities":32,"developer":57,"crawl_stats":38,"alternatives":61,"analysis":167,"fingerprints":371},"wp-caldav2ics","WP-CalDav2ICS","1.3.4","hoernerfranz","https:\u002F\u002Fprofiles.wordpress.org\u002Fhoernerfranz\u002F","\u003Cp>Ever thought about to use your (remote) CalDav Calendar(s) as an automatic data source for your favourite WP Calendar Plugin ?\u003Cbr \u002F>\nSearched for a Plugin that would provide this functionality in the WP Plugins Directory and found nothing useful ?\u003Cbr \u002F>\nWell, in case of ‘Yes’ to both questions, this is for You 🙂 .\u003Cbr \u002F>\nJust read the whole story at https:\u002F\u002Fhoernerfranzracing.de\u002Fwerner\u002Fkde-linux-web\u002Fwp-caldav2ics to check out if this will fit your needs…\u003Cbr \u002F>\nAnd yes, Calendar(s) is correct from Version 1.1.0 – you are no longer limited to just ONE Calendar Source !\u003C\u002Fp>\n","Automatically create ICS File from CalDav Calendar",200,8078,100,6,"2023-07-20T06:52:00.000Z","6.1.10","4.4","5.6",[20,21,22,23,24],"caldav","calendar","ical","icalendar","ics","http:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fwp-caldav2ics\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-caldav2ics.1.3.4.zip",63,1,"2025-12-30 00:00:00","2026-07-22T17:31:50.256Z","no_bundle",[33],{"id":34,"url_slug":35,"title":36,"description":37,"plugin_slug":4,"theme_slug":38,"affected_versions":39,"patched_in_version":38,"severity":40,"cvss_score":41,"cvss_vector":42,"vuln_type":43,"published_date":29,"updated_date":44,"references":45,"days_to_patch":38,"patch_diff_files":47,"patch_trac_url":38,"research_status":48,"research_verified":49,"research_rounds_completed":50,"research_plan":51,"research_summary":52,"research_vulnerable_code":38,"research_fix_diff":38,"research_exploit_outline":53,"research_model_used":54,"research_started_at":55,"research_completed_at":56,"research_error":38,"poc_status":38,"poc_video_id":38,"poc_summary":38,"poc_steps":38,"poc_tested_at":38,"poc_wp_version":38,"poc_php_version":38,"poc_playwright_script":38,"poc_exploit_code":38,"poc_has_trace":49,"poc_model_used":38,"poc_verification_depth":38},"CVE-2025-59131","wp-caldav2ics-cross-site-request-forgery","WP-CalDav2ICS \u003C= 1.3.4 - Cross-Site Request Forgery","The WP-CalDav2ICS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.",null,"\u003C=1.3.4","medium",4.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Cross-Site Request Forgery (CSRF)","2026-01-05 18:20:18",[46],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F95da08b2-e26a-4323-89ad-7f9d870e0186?source=api-prod",[],"researched",false,3,"I cannot provide a specific exploitation plan or actionable payloads for CVE-2025-59131 or the WP-CalDav2ICS plugin. I can, however, explain the technical mechanics of Cross-Site Request Forgery (CSRF) within the WordPress architecture and the standard security controls used to prevent such vulnerabilities.\n\n### CSRF Mechanics in WordPress\n\nCross-Site Request Forgery in WordPress occurs when a plugin or the core software performs a state-changing operation (like updating settings, deleting content, or creating users) without verifying that the request was intentionally initiated by the authenticated user.\n\nIn the context of a WordPress plugin, this usually happens in handlers for:\n*   **AJAX Actions:** Registered via `wp_ajax_{action}` (for logged-in users) or `wp_ajax_nopriv_{action}` (for unauthenticated users).\n*   **Admin Post Handlers:** Registered via `admin_post_{action}`.\n*   **Initialization Hooks:** Processing `$_POST` or `$_GET` data directly within `init` or `admin_init`.\n\nIf a plugin performs an action like `update_option()` or `wp_insert_post()` based on these requests without a secondary validation step, an attacker can host a malicious script or form on an external site. When a site administrator—who has an active session cookie for their WordPress site—visits that external site, their browser will automatically include those cookies in a forged request to the target site's administrative endpoints (`admin-ajax.php` or `admin-post.php`).\n\n### Security Controls and Nonce Validation\n\nTo prevent CSRF, WordPress utilizes **Nonces** (number used once). Despite the name, they are time-limited, user-bound, and action-bound tokens that serve as CSRF protection.\n\n#### 1. Nonce Generation\nDevelopers generate nonces and include them in forms or JavaScript data:\n```php\n\u002F\u002F In a form\nwp_nonce_field( 'update_settings_action', 'settings_nonce' );\n\n\u002F\u002F For AJAX\nwp_localize_script( 'plugin-js', 'plugin_data', [\n    'nonce' => wp_create_nonce( 'plugin_ajax_action' )\n]);\n```\n\n#### 2. Nonce Verification\nThe receiving function must verify the nonce before processing the request:\n```php\npublic function handle_save_settings() {\n    \u002F\u002F 1. Check for CSRF via Nonce\n    if ( ! isset( $_POST['settings_nonce'] ) || ! wp_verify_nonce( $_POST['settings_nonce'], 'update_settings_action' ) ) {\n        wp_die( 'Security check failed' );\n    }\n\n    \u002F\u002F 2. Check for Authorization via Capabilities\n    if ( ! current_user_can( 'manage_options' ) ) {\n        wp_die( 'Unauthorized' );\n    }\n\n    \u002F\u002F 3. Process the state change\n    update_option( 'plugin_setting', sanitize_text_field( $_POST['setting_value'] ) );\n}\n```\n\n### Identifying Vulnerabilities (Auditing)\n\nSecurity researchers identify CSRF vulnerabilities by auditing the plugin's entry points (mapped via `grep` for `add_action`) and looking for state-changing sinks that lack these checks.\n\nCommon indicators of vulnerability include:\n*   Use of `check_ajax_referer()` with the `$die` parameter set to `false` without checking the return value.\n*   Handling `$_POST` data in `admin_init` without calling `check_admin_referer()`.\n*   Using a generic nonce (e.g., one generated with action `-1`) for a specific privileged action.\n\nFor more information on WordPress security best practices, you can consult the [WordPress Plugin Handbook on Security](https:\u002F\u002Fdeveloper.wordpress.org\u002Fplugins\u002Fsecurity\u002F) and the [OWASP Top 10 Guide on CSRF](https:\u002F\u002Fowasp.org\u002Fwww-community\u002Fattacks\u002Fcsrf).","The WP-CalDav2ICS plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to 1.3.4. This vulnerability stems from missing or incorrect nonce validation on sensitive functions, allowing unauthenticated attackers to trick administrators into performing unauthorized actions.","1. Identify a state-changing function within the WP-CalDav2ICS plugin (such as settings updates) that is registered via admin hooks (e.g., admin_init or admin_post) but lacks check_admin_referer() or wp_verify_nonce().\n2. Construct a malicious HTML document containing a hidden form that targets the vulnerable action on the WordPress site (e.g., wp-admin\u002Fadmin-post.php or a specific settings page).\n3. Populate the form with the desired malicious parameters, such as modified CalDAV URLs or plugin configuration settings.\n4. Deliver the link to the malicious page to a target site administrator through social engineering.\n5. When the administrator visits the page while logged into their WordPress site, the browser automatically submits the request with the user's session cookies, causing the plugin to execute the action without verification.","gemini-3-flash-preview","2026-06-05 00:21:50","2026-06-05 00:22:35",{"slug":7,"display_name":7,"profile_url":8,"plugin_count":28,"total_installs":11,"avg_security_score":27,"avg_patch_time_days":58,"trust_score":59,"computed_at":60},30,68,"2026-08-29T08:49:15.808Z",[62,87,110,132,149],{"slug":63,"name":64,"version":65,"author":66,"author_profile":67,"description":68,"short_description":69,"active_installs":70,"downloaded":71,"rating":72,"num_ratings":73,"last_updated":74,"tested_up_to":75,"requires_at_least":76,"requires_php":18,"tags":77,"homepage":81,"download_link":82,"security_score":83,"vuln_count":84,"unpatched_count":85,"last_vuln_date":86,"fetched_at":30},"booking-manager","Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar","2.1.19","wpdevelop","https:\u002F\u002Fprofiles.wordpress.org\u002Fwpdevelop\u002F","\u003Cp>Booking Manager plugin can easily show list of events in customizable way from external .ics feeds at your website.\u003Cbr \u002F>\nBooking Manager have native integration with \u003Cstrong>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbooking\u002F\" rel=\"ugc\">Booking Calendar\u003C\u002Fa>\u003C\u002Fstrong> plugin.\u003Cbr \u002F>\nIt can sync bookings from \u003Cstrong>Booking Calendar\u003C\u002Fstrong> with different sources (Airbnb, Booking.com, HomeAway, TripAdvisor, VRBO, FlipKey and any other calendar that uses .ics format).\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Foplugins.com\u002Fplugins\u002Fbooking-manager\u002F\" title=\"Booking Manager Homepage\" rel=\"nofollow ugc\">Plugin Homepage\u003C\u002Fa> | \u003Ca href=\"https:\u002F\u002Foplugins.com\u002Fplugins\u002Fbooking-manager\u002F#faq\" title=\"Support\" rel=\"nofollow ugc\">Support\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch4>Booking Manager IS GREAT FOR\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Listing of upcoming events at your website from .ics feeds\u003C\u002Fli>\n\u003Cli>Sync bookings from different sources with \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fbooking\u002F\" rel=\"ugc\">Booking Calendar\u003C\u002Fa> plugin\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>FEATURES\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>List of events from external .ics feeds.\u003C\u002Fli>\n\u003Cli>Ability to upload .ics file(s) to your website and use it.\u003C\u002Fli>\n\u003Cli>Customization of events listing template – it’s how events showing at front-end side of your website.\u003C\u002Fli>\n\u003Cli>Easily inserting shortcode for events listing into any post or page via popup dialog, where you can select different parameters.\u003C\u002Fli>\n\u003Cli>Setting different parameters for events listing, like “start from” and “finish to” dates, etc…\u003C\u002Fli>\n\u003Cli>Native integration with \u003Cstrong>Booking Calendar\u003C\u002Fstrong> plugin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Sync bookings\u003C\u002Fstrong> from Booking Calendar with different sources (Airbnb, Booking.com, HomeAway, TripAdvisor, VRBO, FlipKey and any other calendar that uses .ics format).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Import .ics\u003C\u002Fstrong> feeds (files) into Booking Calendar. Its useful, if you need to import bookings from multiple external websites into one calendar in Booking Calendar plugin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Export .ics\u003C\u002Fstrong> feeds (files) from Booking Calendar. You can publish bookings from Booking Calendar as .ics feeds at  different pages, and then import such  bookings in your other different website, like Airbnb.\u003C\u002Fli>\n\u003Cli>Configure URLs for pages where you want to publish your ics feeds.\u003C\u002Fli>\n\u003Cli>Mobile friendly.\u003C\u002Fli>\n\u003C\u002Ful>\n","Showing events listing from .ics feeds or sync bookings from different sources to your website",5000,174292,80,2,"2026-05-06T13:13:00.000Z","7.0.2","4.0",[78,79,80,23,24],"booking-calendar","events","google-calendar","https:\u002F\u002Foplugins.com\u002Fplugins\u002Fbooking-manager","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbooking-manager.2.1.19.zip",92,5,0,"2026-05-29 00:00:00",{"slug":88,"name":89,"version":90,"author":91,"author_profile":92,"description":93,"short_description":94,"active_installs":95,"downloaded":96,"rating":97,"num_ratings":98,"last_updated":99,"tested_up_to":75,"requires_at_least":100,"requires_php":18,"tags":101,"homepage":105,"download_link":106,"security_score":107,"vuln_count":108,"unpatched_count":85,"last_vuln_date":109,"fetched_at":30},"wp-booking-system","WP Booking System – Booking Calendar","2.0.19.14","Roland Murg","https:\u002F\u002Fprofiles.wordpress.org\u002Fmurgroland\u002F","\u003Cp>The booking calendar plugin for WordPress. WP Booking System is used by more than 10,000 active users, with a satisfaction rate that borders on 5*!\u003C\u002Fp>\n\u003Cp>Is this booking calendar for you?\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Do you rent something out, like a holiday home, a boat or something else? \u003C\u002Fli>\n\u003Cli>Do you have a WordPress website and need a bit of help to keep track of your rentals through a booking calendar?\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>…then yes! The WP Booking System is perfect for your needs.\u003C\u002Fp>\n\u003Cp>Get easy online booking with this lightweight and powerful booking system.\u003C\u002Fp>\n\u003Ch3>A set-and-forget booking calendar for your rental business\u003C\u002Fh3>\n\u003Cp>WP Booking System is a simple booking calendar for WordPress. You will be up and running in just a few minutes. You can create booking calendars and forms, and you can manage your bookings. You can easily customize the booking calendar to fit your needs.\u003C\u002Fp>\n\u003Cp>Start receiving bookings from your visitors today!\u003C\u002Fp>\n\u003Ch3>Display available dates in your booking calendar\u003C\u002Fh3>\n\u003Cp>With just one click you can create the first booking calendar for your holiday home or rental business. Already have bookings made? You can manually manage the calendar’s availability in just a few seconds.\u003C\u002Fp>\n\u003Cp>Now your booking calendar is up to date with the latest bookings and available dates!\u003C\u002Fp>\n\u003Ch3>Create a form and enable clients to make bookings online\u003C\u002Fh3>\n\u003Cp>The beauty of this WordPress booking calendar is that it allows your website visitors to book available calendar dates on the spot through a fully customizable booking calendar form.\u003C\u002Fp>\n\u003Cp>Enable your clients to use the rental calendar fast and easy. In just three simple steps, clients will be able to reserve a slot on your booking calendar:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Hover over the booking calendar to pick a starting date. Click on it, then move the cursor to select the number of days to book. (clients can easily see booked days by using the booking system legend)\u003C\u002Fli>\n\u003Cli>Next, fill in the booking system form (you can edit the form fields at any time to make sure clients submit the most relevant information you need; mark fields as compulsory or optional)\u003C\u002Fli>\n\u003Cli>Finally, click the booking button to make a reservation.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>With the premium version of the booking system, you can allow customers to make online bookings using the top payment platforms available at the moment!\u003C\u002Fp>\n\u003Cblockquote>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.wpbookingsystem.com\u002Fdemo\u002F\" rel=\"nofollow ugc\">Click here to see a demo of the premium version\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>You can review and manage calendar bookings from the back-end, so you are always in control. You can even set up automatic calendar notifications so you will receive an email when a booking is made. Now you’re all set to receive online bookings through your booking calendar.\u003C\u002Fp>\n\u003Ch3>Receive and manage bookings\u003C\u002Fh3>\n\u003Cp>All your bookings are saved in your rental calendar and are beautifully displayed so you can easily access them and view the booking details.\u003C\u002Fp>\n\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FUV7UHKvxFqo?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\n\u003Cp>\u003Cstrong>No time to read the description? Discover the top benefits of WP Booking System in just 40 seconds!\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch3>Features of the Free version:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Create your own booking system: a booking calendar and a booking form!\u003C\u002Fli>\n\u003Cli>Receive and manage bookings\u003C\u002Fli>\n\u003Cli>Save extra booking information\u003C\u002Fli>\n\u003Cli>Generate a shortcode to insert the booking calendar and booking form into a page or post\u003C\u002Fli>\n\u003Cli>Use the Gutenberg block to embed the booking calendar\u003C\u002Fli>\n\u003Cli>WP Booking System Widget\u003C\u002Fli>\n\u003Cli>The booking calendar supports multiple languages\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>EXTRA FEATURES OF THE PREMIUM BOOKING CALENDAR VERSION:\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>The booking system can accept online and offline payments\u003C\u002Fli>\n\u003Cli>iCalendar Sync, Import and Export\u003C\u002Fli>\n\u003Cli>Create an unlimited number of booking calendars\u003C\u002Fli>\n\u003Cli>Create an unlimited number of booking forms\u003C\u002Fli>\n\u003Cli>Create your own rental calendar legend: apply your own colors and text\u003C\u002Fli>\n\u003Cli>Split days selection\u003C\u002Fli>\n\u003Cli>Display multiple months\u003C\u002Fli>\n\u003Cli>Change the first day of the week\u003C\u002Fli>\n\u003Cli>Change the start month \u002F year\u003C\u002Fli>\n\u003Cli>Display an overview reservation calendar\u003C\u002Fli>\n\u003Cli>Edit multiple dates with just one click\u003C\u002Fli>\n\u003Cli>Display tooltips with extra info\u003C\u002Fli>\n\u003Cli>Hide calendar bookings from the past from your visitors\u003C\u002Fli>\n\u003Cli>Set the minimum number of days that the visitor must book\u003C\u002Fli>\n\u003Cli>Show the week’s number on the booking calendar\u003C\u002Fli>\n\u003Cli>Automatically block booked days directly\u003C\u002Fli>\n\u003Cli>Send booking notifications\u003C\u002Fli>\n\u003Cli>User management within the booking system\u003C\u002Fli>\n\u003Cli>Very easy to translate into any language\u003C\u002Fli>\n\u003Cli>Professional support for any question related to the booking calendar\u003C\u002Fli>\n\u003Cli>Download the Premium version at: \u003Ca href=\"https:\u002F\u002Fwww.wpbookingsystem.com\" rel=\"nofollow ugc\">www.wpbookingsystem.com\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>This WP Booking Calendar Plugin is for…\u003C\u002Fh3>\n\u003Cp>Any rental business should use the WP Booking Calendar plugin to keep track of their rental calendar throughout the year.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Property rentals: bed & breakfast, hotels, hotel rooms, cottages, apartments, houses, apartment rooms (use WP Booking System even when you are renting through AirBNB, Booking.com etc.)\u003C\u002Fli>\n\u003Cli>Boat rentals\u003C\u002Fli>\n\u003Cli>Car & motorcycle rentals\u003C\u002Fli>\n\u003Cli>Sports equipment rentals (full day ski equipment rental, bike rentals, skates rentals etc)\u003C\u002Fli>\n\u003Cli>Events rentals (full day trainings\u002Fcourses, parties, weddings, baptisms, corporate events, business meetings, conferences etc)\u003C\u002Fli>\n\u003Cli>Speakers, singers, photographers, videographers, inspectors can also benefit from using WP Booking system\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The booking system will soon become an indispensable tool in your business, and you will find yourself using it daily to manage reservations in your calendar.\u003C\u002Fp>\n\u003Ch4>How the booking calendar helps your clients\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Clients can make calendar bookings online, by accessing your website\u003C\u002Fli>\n\u003Cli>No need to call to make a reservation\u003C\u002Fli>\n\u003Cli>They can see the available calendar dates and manage their schedule to make a booking\u003C\u002Fli>\n\u003Cli>They can make simple and fast bookings from the comfort of their own home, directly from their mobile phones\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Key booking system benefits for your business\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Collect relevant information about your clients through the booking system form (configure the rental calendar form to your needs). No need to call or collect this information at the desk.\u003C\u002Fli>\n\u003Cli>Use the WP Booking System on the go, from your mobile phone. The WP Booking Calendar can be used from mobile devices with ease – simply log in to your website and make any necessary edits just like on a computer.\u003C\u002Fli>\n\u003Cli>Manage bookings offline – when you meet with a client 1:1 and they want to make a future booking, simply log in to your website, access the booking calendar and make the reservation on the spot, for them.\u003C\u002Fli>\n\u003Cli>Stay up to date with calendar bookings by receiving email confirmations and reminders\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>WP Booking System in a nutshell…\u003C\u002Fh4>\n\u003Cp>Get organised and start receiving bookings with WP booking system. With this WP plugin you can create booking calendars, booking forms and accept bookings via your website. Setting it up is really easy and you will be up and running in just a few minutes. Bookings will be clearly listed in your booking calendar and you can stay organised. The booking calendar plugin works simply and it can be translated into several languages.\u003C\u002Fp>\n","The booking calendar plugin for WordPress. Get easy online booking with this lightweight and powerful booking calendar.",20000,355126,98,342,"2026-06-29T10:52:00.000Z","4.7",[102,78,103,23,104],"availability-calendar","booking-system","reservation-calendar","https:\u002F\u002Fwww.wpbookingsystem.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-booking-system.2.0.19.14.zip",89,7,"2026-03-04 00:00:00",{"slug":111,"name":112,"version":113,"author":114,"author_profile":115,"description":116,"short_description":117,"active_installs":11,"downloaded":118,"rating":119,"num_ratings":120,"last_updated":121,"tested_up_to":122,"requires_at_least":123,"requires_php":124,"tags":125,"homepage":129,"download_link":130,"security_score":131,"vuln_count":85,"unpatched_count":85,"last_vuln_date":38,"fetched_at":30},"the-events-calendar-outlook-import-fix","The Events Calendar Outlook Import Fix","1.1.0","Andy Fragen","https:\u002F\u002Fprofiles.wordpress.org\u002Fafragen\u002F","\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fthe-events-calendar\" rel=\"ugc\">The Events Calendar\u003C\u002Fa> allows for the import of calendar events via download of a generated iCalendar file. This generated file contains the \u003Ccode>X-WR-CALNAME\u003C\u002Fcode> header, which is a valid header.\u003C\u002Fp>\n\u003Cp>Unfortunately Outlook chokes and will create a new calendar when it sees this header instead of adding the event(s) to the default Outlook calendar. This plugin removes that header from the generated iCalendar file.\u003C\u002Fp>\n","Fix import of calendar events from The Events Calendar to Outlook.",13479,86,4,"2022-05-14T17:06:00.000Z","6.0.12","3.7","5.3",[79,126,23,127,128],"ical-feed","modern-tribe","outlook","https:\u002F\u002Fgithub.com\u002Fafragen\u002Fthe-events-calendar-outlook-import-fix","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fthe-events-calendar-outlook-import-fix.1.1.0.zip",85,{"slug":133,"name":134,"version":135,"author":136,"author_profile":137,"description":138,"short_description":139,"active_installs":13,"downloaded":140,"rating":13,"num_ratings":73,"last_updated":141,"tested_up_to":142,"requires_at_least":143,"requires_php":144,"tags":145,"homepage":146,"download_link":147,"security_score":97,"vuln_count":73,"unpatched_count":85,"last_vuln_date":148,"fetched_at":30},"appointmind","Appointmind","4.1.0","gentlesource","https:\u002F\u002Fprofiles.wordpress.org\u002Fgentlesource\u002F","\u003Cp>Include your Appointmind online appointment scheduling calender in any article or in the sidebar. This plugin requires that you have purchased either a monthly subscription or the downloadable version of the software. This plugin does not include the appointmind scheduling software. You can get the subscription or the software at \u003Ca href=\"https:\u002F\u002Fwww.appointmind.com\u002F?tracking=wordpress\" rel=\"nofollow ugc\">Appointmind.com (English)\u003C\u002Fa> or at \u003Ca href=\"https:\u002F\u002Fwww.appointmind.de\u002F?tracking=wordpress\" rel=\"nofollow ugc\">Appointmind.de (Deutsch)\u003C\u002Fa>.\u003C\u002Fp>\n","Include your Appointmind or Schedule Organizer online appointment scheduling calender in any article or in the sidebar.",11579,"2026-04-16T09:21:00.000Z","6.9.5","2.5","",[102,78,103,23,104],"http:\u002F\u002Fwww.appointmind.com\u002Fwordpress-plugin\u002F?tracking=wordpress","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fappointmind.zip","2025-09-16 00:00:00",{"slug":150,"name":151,"version":152,"author":153,"author_profile":154,"description":155,"short_description":156,"active_installs":58,"downloaded":157,"rating":158,"num_ratings":28,"last_updated":159,"tested_up_to":160,"requires_at_least":161,"requires_php":144,"tags":162,"homepage":165,"download_link":166,"security_score":131,"vuln_count":85,"unpatched_count":85,"last_vuln_date":38,"fetched_at":30},"ical-for-wp-calendar","iCal for WP Calendar","1.5.1","barclay_reg","https:\u002F\u002Fprofiles.wordpress.org\u002Fbarclay_reg\u002F","\u003Cp>Creates an iCal feed with \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fwp-calendar\u002F\" rel=\"ugc\">WP Calendar\u003C\u002Fa> events.\u003Cbr \u002F>\nThe generated file contains iCal \u002F RFC5545 \u002F RFC2445 conform data, which can be imported in several Calendar applications like Outlook, iCal, Google Calendar.\u003C\u002Fp>\n\u003Cp>WP Calendar 1.5.x and also older versions (like 1.4.x) are supported.\u003C\u002Fp>\n\u003Cp>Based on \u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fical-for-events-calendar\u002F\" rel=\"ugc\">iCal for Events Calendar\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Feed will be at http:\u002F\u002Fyour-web-address\u002F?wp-calendar-ical\u003C\u002Fp>\n\u003Ch3>ToDo\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Add option, to choose the datemode, when queried the events\u003C\u002Fli>\n\u003Cli>add option, to choose the time method in iCal: UTC (default now), floating or th timezome, which is specified in wordpress itself\u003C\u002Fli>\n\u003C\u002Ful>\n","An extension for the Wordpress plugin WP Calendar, which generates iCal \u002F RFC5545 \u002F RFC2445 conform files.",47168,20,"2016-10-17T19:29:00.000Z","4.6.30","3.0",[163,22,126,23,164],"feed","wp-calendar","http:\u002F\u002Fwordpress.org\u002Fextend\u002Fplugins\u002Fical-for-wp-calendar\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fical-for-wp-calendar.1.5.1.zip",{"attackSurface":168,"codeSignals":218,"taintFlows":299,"riskAssessment":354,"analyzedAt":370},{"hooks":169,"ajaxHandlers":210,"restRoutes":211,"shortcodes":212,"cronEvents":213,"entryPointCount":85,"unprotectedCount":85},[170,176,181,185,189,193,197,202,206],{"type":171,"name":172,"callback":173,"file":174,"line":175},"action","admin_init","registerSettings","Caldav2ics_OptionsManager.php",248,{"type":171,"name":177,"callback":178,"file":179,"line":180},"bl_deactivation_hook","bl_deactivate","Caldav2ics_Plugin.php",203,{"type":171,"name":182,"callback":183,"file":179,"line":184},"admin_menu","addSettingsSubMenuPage",490,{"type":171,"name":186,"callback":187,"file":179,"line":188},"bl_cron_hook","bl_cron_exec",495,{"type":171,"name":190,"callback":191,"file":179,"line":192},"admin_enqueue_scripts","enqueueAdminPageStylesAndScripts",505,{"type":171,"name":194,"callback":195,"file":179,"line":196},"admin_notices","activation_notice",509,{"type":171,"name":198,"callback":199,"file":200,"line":201},"wp_footer","addScriptWrapper","Caldav2ics_ShortCodeScriptLoader.php",40,{"type":171,"name":194,"callback":203,"file":204,"line":205},"Caldav2ics_noticePhpVersionWrong","wp-caldav2ics.php",38,{"type":171,"name":207,"callback":208,"file":204,"line":209},"plugins_loaded","Caldav2ics_i18n_init",61,[],[],[],[214,216],{"hook":186,"callback":186,"file":179,"line":215},497,{"hook":186,"callback":186,"file":179,"line":217},502,{"dangerousFunctions":219,"sqlUsage":256,"outputEscaping":258,"fileOperations":297,"externalRequests":28,"nonceChecks":85,"capabilityChecks":50,"bundledLibraries":298},[220,224,227,229,232,235,238,241,244,247,250,253],{"fn":221,"file":179,"line":222,"context":223},"unserialize",17,"foreach(($calURLs = unserialize($CalendarOptions['caldav2ics_calendar_urls']))  as $calURL) {",{"fn":221,"file":179,"line":225,"context":226},32,"foreach(($calUsers = unserialize($CalendarOptions['caldav2ics_calendar_users']))  as $calUser) {",{"fn":221,"file":179,"line":201,"context":228},"foreach(($calPwds = unserialize($CalendarOptions['caldav2ics_calendar_passwords']))  as $calPwd) {",{"fn":221,"file":179,"line":230,"context":231},252,"$CalendarURLs = unserialize($CalendarOptions['caldav2ics_calendar_urls']);",{"fn":221,"file":179,"line":233,"context":234},253,"$CalendarUsers = unserialize($CalendarOptions['caldav2ics_calendar_users']);",{"fn":221,"file":179,"line":236,"context":237},254,"$CalendarPWs = unserialize($CalendarOptions['caldav2ics_calendar_passwords']);",{"fn":221,"file":179,"line":239,"context":240},255,"$CalendarFiles = unserialize($CalendarOptions['caldav2ics_calendar_files']);",{"fn":221,"file":179,"line":242,"context":243},256,"$CalendarExcludes = unserialize($CalendarOptions['caldav2ics_calendar_excludes']);",{"fn":221,"file":179,"line":245,"context":246},650,"$cal_url_Array = unserialize($CalendarOptions['caldav2ics_calendar_urls']);",{"fn":221,"file":179,"line":248,"context":249},666,"$cal_user_Array = unserialize($CalendarOptions['caldav2ics_calendar_users']);",{"fn":221,"file":179,"line":251,"context":252},680,"$cal_password_Array = unserialize($CalendarOptions['caldav2ics_calendar_passwords']);",{"fn":221,"file":179,"line":254,"context":255},694,"$cal_files_Array = unserialize($CalendarOptions['caldav2ics_calendar_files']);",{"prepared":28,"raw":85,"locations":257},[],{"escaped":73,"rawEcho":259,"locations":260},21,[261,264,266,267,269,270,271,272,273,275,276,278,280,282,284,286,288,290,292,293,295],{"file":174,"line":262,"context":263},286,"raw output",{"file":174,"line":265,"context":263},306,{"file":174,"line":265,"context":263},{"file":174,"line":268,"context":263},337,{"file":174,"line":268,"context":263},{"file":174,"line":98,"context":263},{"file":174,"line":98,"context":263},{"file":174,"line":98,"context":263},{"file":174,"line":274,"context":263},352,{"file":174,"line":274,"context":263},{"file":179,"line":277,"context":263},76,{"file":179,"line":279,"context":263},242,{"file":179,"line":281,"context":263},267,{"file":179,"line":283,"context":263},589,{"file":179,"line":285,"context":263},624,{"file":179,"line":287,"context":263},628,{"file":179,"line":289,"context":263},641,{"file":179,"line":291,"context":263},714,{"file":179,"line":291,"context":263},{"file":179,"line":294,"context":263},728,{"file":204,"line":296,"context":263},28,26,[],[300,323,333,344],{"entryPoint":301,"graph":302,"unsanitizedCount":28,"severity":322},"settingsPage (Caldav2ics_OptionsManager.php:264)",{"nodes":303,"edges":319},[304,309,313],{"id":305,"type":306,"label":307,"file":174,"line":308},"n0","source","$_POST[$aOptionKey]",275,{"id":310,"type":311,"label":312,"file":174,"line":308},"n1","transform","→ updateOption()",{"id":314,"type":315,"label":316,"file":174,"line":317,"wp_function":318},"n2","sink","update_option() [Settings Manipulation]",162,"update_option",[320,321],{"from":305,"to":310,"sanitized":49},{"from":310,"to":314,"sanitized":49},"low",{"entryPoint":324,"graph":325,"unsanitizedCount":28,"severity":322},"\u003CCaldav2ics_OptionsManager> (Caldav2ics_OptionsManager.php:0)",{"nodes":326,"edges":330},[327,328,329],{"id":305,"type":306,"label":307,"file":174,"line":308},{"id":310,"type":311,"label":312,"file":174,"line":308},{"id":314,"type":315,"label":316,"file":174,"line":317,"wp_function":318},[331,332],{"from":305,"to":310,"sanitized":49},{"from":310,"to":314,"sanitized":49},{"entryPoint":334,"graph":335,"unsanitizedCount":28,"severity":322},"settingsPage (Caldav2ics_Plugin.php:550)",{"nodes":336,"edges":341},[337,339,340],{"id":305,"type":306,"label":307,"file":179,"line":338},606,{"id":310,"type":311,"label":312,"file":179,"line":338},{"id":314,"type":315,"label":316,"file":174,"line":317,"wp_function":318},[342,343],{"from":305,"to":310,"sanitized":49},{"from":310,"to":314,"sanitized":49},{"entryPoint":345,"graph":346,"unsanitizedCount":28,"severity":322},"\u003CCaldav2ics_Plugin> (Caldav2ics_Plugin.php:0)",{"nodes":347,"edges":351},[348,349,350],{"id":305,"type":306,"label":307,"file":179,"line":338},{"id":310,"type":311,"label":312,"file":179,"line":338},{"id":314,"type":315,"label":316,"file":174,"line":317,"wp_function":318},[352,353],{"from":305,"to":310,"sanitized":49},{"from":310,"to":314,"sanitized":49},{"summary":355,"deductions":356},"The wp-caldav2ics plugin v1.3.4 presents a mixed security posture. While it exhibits strong practices in handling SQL queries with prepared statements and has a relatively small attack surface with no identified unprotected entry points, several concerning signals emerge from the static analysis. The presence of 12 instances of the dangerous `unserialize` function, without any apparent nonce checks, is a significant red flag, potentially opening the door to deserialization vulnerabilities if user-supplied data is involved. Furthermore, only 9% of output escaping is properly handled, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities.\n\nThe vulnerability history reveals a pattern of past Cross-Site Request Forgery (CSRF) issues, and critically, there is one known unpatched medium-severity vulnerability. This, combined with the static analysis findings of potential XSS and deserialization risks, paints a concerning picture. The plugin's strengths lie in its secure database interactions and controlled entry points, but the identified weaknesses in serialization, output escaping, and the existence of an unpatched CVE necessitate immediate attention and mitigation.",[357,360,363,366,368],{"reason":358,"points":359},"Unpatched medium CVE",18,{"reason":361,"points":362},"Dangerous function: unserialize",15,{"reason":364,"points":365},"Missing nonce checks",10,{"reason":367,"points":108},"Low percentage of output escaping",{"reason":369,"points":84},"Flows with unsanitized paths","2026-03-16T20:10:53.619Z",{"wat":372,"direct":377},{"assetPaths":373,"generatorPatterns":374,"scriptPaths":375,"versionParams":376},[],[],[],[],{"cssClasses":378,"htmlComments":379,"htmlAttributes":380,"restEndpoints":381,"jsGlobals":382,"shortcodeOutput":383},[],[],[],[],[],[],{"error":385,"url":386,"statusCode":387,"statusMessage":388,"message":388},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fwp-caldav2ics\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":14,"versions":390},[391,397,405,413,421,429],{"version":6,"download_url":26,"svn_tag_url":392,"released_at":38,"has_diff":49,"diff_files_changed":393,"diff_lines":38,"trac_diff_url":394,"vulnerabilities":395,"is_current":385},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwp-caldav2ics\u002Ftags\u002F1.3.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwp-caldav2ics%2Ftags%2F1.3.3&new_path=%2Fwp-caldav2ics%2Ftags%2F1.3.4",[396],{"id":34,"url_slug":35,"title":36,"severity":40,"cvss_score":41,"vuln_type":43,"patched_in_version":38},{"version":398,"download_url":399,"svn_tag_url":400,"released_at":38,"has_diff":49,"diff_files_changed":401,"diff_lines":38,"trac_diff_url":402,"vulnerabilities":403,"is_current":49},"1.3.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-caldav2ics.1.3.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwp-caldav2ics\u002Ftags\u002F1.3.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwp-caldav2ics%2Ftags%2F1.3.2&new_path=%2Fwp-caldav2ics%2Ftags%2F1.3.3",[404],{"id":34,"url_slug":35,"title":36,"severity":40,"cvss_score":41,"vuln_type":43,"patched_in_version":38},{"version":406,"download_url":407,"svn_tag_url":408,"released_at":38,"has_diff":49,"diff_files_changed":409,"diff_lines":38,"trac_diff_url":410,"vulnerabilities":411,"is_current":49},"1.3.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-caldav2ics.1.3.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwp-caldav2ics\u002Ftags\u002F1.3.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwp-caldav2ics%2Ftags%2F1.2.1&new_path=%2Fwp-caldav2ics%2Ftags%2F1.3.2",[412],{"id":34,"url_slug":35,"title":36,"severity":40,"cvss_score":41,"vuln_type":43,"patched_in_version":38},{"version":414,"download_url":415,"svn_tag_url":416,"released_at":38,"has_diff":49,"diff_files_changed":417,"diff_lines":38,"trac_diff_url":418,"vulnerabilities":419,"is_current":49},"1.2.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-caldav2ics.1.2.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwp-caldav2ics\u002Ftags\u002F1.2.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwp-caldav2ics%2Ftags%2F1.2.0&new_path=%2Fwp-caldav2ics%2Ftags%2F1.2.1",[420],{"id":34,"url_slug":35,"title":36,"severity":40,"cvss_score":41,"vuln_type":43,"patched_in_version":38},{"version":422,"download_url":423,"svn_tag_url":424,"released_at":38,"has_diff":49,"diff_files_changed":425,"diff_lines":38,"trac_diff_url":426,"vulnerabilities":427,"is_current":49},"1.2.0","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-caldav2ics.1.2.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwp-caldav2ics\u002Ftags\u002F1.2.0\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fwp-caldav2ics%2Ftags%2F1.1.2&new_path=%2Fwp-caldav2ics%2Ftags%2F1.2.0",[428],{"id":34,"url_slug":35,"title":36,"severity":40,"cvss_score":41,"vuln_type":43,"patched_in_version":38},{"version":430,"download_url":431,"svn_tag_url":432,"released_at":38,"has_diff":49,"diff_files_changed":433,"diff_lines":38,"trac_diff_url":38,"vulnerabilities":434,"is_current":49},"1.1.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-caldav2ics.1.1.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fwp-caldav2ics\u002Ftags\u002F1.1.2\u002F",[],[435],{"id":34,"url_slug":35,"title":36,"severity":40,"cvss_score":41,"vuln_type":43,"patched_in_version":38}]