WordPress My Calendar plugin versions before 3.4.22 are vulnerable to an unauthenticated SQL injection within the 'from' and 'to' parameters of the '/my-calendar/v1/events' REST route.
id: CVE-2023-6360
info:
name: WordPress My Calendar <3.4.22 - SQL Injection
author: xxcdd
sev
...