WordPress Calendar Event Multi View plugin before 1.4.01 contains an unauthenticated reflected cross-site scripting vulnerability. It does not sanitize or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php).
id: CVE-2021-24498
info:
name: WordPress Calendar Event Multi View <1.4.01 - Cross-Site Scripting
...