WordPress Calendar Event Multi View plugin before 1.4.01 contains an unauthenticated reflected cross-site scripting vulnerability. It does not sanitize or escape the ‘start’ and ‘end’ GET parameters before outputting them in the page (via php/edit.php).
View the template here CVE-2021-24498.yaml
References:
https://wpscan.com/vulnerability/3c5a5187-42b3-4f88-9b0e-4fdfa1c39e86