A vulnerability was found in smub Sugar Calendar Plugin up to 3.3.0 on WordPress and classified as problematic. Affected by this issue is the function
add_query_arg/remove_query_arg
. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-10878. The attack may be launched remotely. There is no exploit available.