WordPress MF Gig Calendar plugin 1.1 and prior contains a reflected cross-site scripting vulnerability. It does not sanitize or escape the id GET parameter before outputting back in the admin dashboard when editing an event.
id: CVE-2021-24510
info:
name: WordPress MF Gig Calendar <=1.1 - Cross-Site Scripting
author: d
...