WordPress plugin My Calendar <= 3.1.9 is susceptible to reflected cross-site scripting which can be triggered via unescaped usage of URL parameters in multiple locations throughout the site.
View the template here CVE-2019-15713.yaml
References:
https://github.com/ARPSyndicate/cvemon