WordPress plugin My Calendar <= 3.1.9 is susceptible to reflected cross-site scripting which can be triggered via unescaped usage of URL parameters in multiple locations throughout the site.
id: CVE-2019-15713
info:
name: WordPress My Calendar <= 3.1.9 - Cross-Site Scripting
author: da
...