CVE-2021-24496: Community Event < 1.4.8 - Reflected Cross-Site Scripting (XSS)
The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24496?
CVE-2021-24496 is classified as a reflected Cross-Site Scripting vulnerability that poses a moderate risk to affected systems.
How do I fix CVE-2021-24496?
To fix CVE-2021-24496, you should update the Community Events WordPress plugin to version 1.4.8 or later.
Who is affected by CVE-2021-24496?
CVE-2021-24496 affects users of the Community Events WordPress plugin versions prior to 1.4.8.
What are the consequences of exploiting CVE-2021-24496?
Exploiting CVE-2021-24496 can allow attackers to execute arbitrary scripts in the context of an administrative session, potentially leading to unauthorized actions.
Is CVE-2021-24496 easily exploitable?
Yes, CVE-2021-24496 is considered easily exploitable due to the lack of input validation and sanitization in the affected parameters.