Browse all 6 CVE security advisories affecting joedolson. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Joedolson develops WordPress accessibility plugins, primarily serving website owners needing compliance solutions. Historically, vulnerabilities have included stored cross-site scripting (XSS), arbitrary file inclusion, and insufficient input validation leading to remote code execution. Notable incidents include CVE-2021-24732, which allowed unauthenticated attackers to execute arbitrary PHP code via crafted requests, and CVE-2021-24733, enabling privilege escalation through improper capability checks. These vulnerabilities often stem from inadequate sanitization of user-supplied data and improper implementation of WordPress security mechanisms. The plugin's core functionality frequently interacts with sensitive WordPress functions, increasing potential attack surface when security controls are misconfigured or bypassed.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-7525 | My Calendar <= 3.7.9 - Authenticated (Custom+) Missing Authorization to Unauthorized Event Publication via 'event_approved' Parameter — My Calendar – Accessible Event ManagerCWE-862 | 4.3 | Medium | 2026-05-14 |
| CVE-2026-2355 | My Calendar – Accessible Event Manager <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes — My Calendar – Accessible Event ManagerCWE-79 | 6.4 | Medium | 2026-03-04 |
This page lists every published CVE security advisory associated with joedolson. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.