CVE-2021-24498: Calendar Event Multi View < 1.4.01 - Unauthenticated Reflected Cross-Site Scripting (XSS)
The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Calendar Event Multi View WordPress plugin?
The vulnerability ID for the Calendar Event Multi View WordPress plugin is CVE-2021-24498.
What is the severity rating of CVE-2021-24498?
CVE-2021-24498 has a severity rating of medium with a CVSS score of 6.1.
What is the affected version of the Calendar Event Multi View WordPress plugin?
The affected version of the Calendar Event Multi View WordPress plugin is 1.4.01.
What is the CWE number associated with CVE-2021-24498?
The CWE number associated with CVE-2021-24498 is CWE-79.
How can I fix the Cross-Site Scripting issue in the Calendar Event Multi View WordPress plugin?
To fix the Cross-Site Scripting issue in the Calendar Event Multi View WordPress plugin, apply the latest version of the plugin (version 1.4.01) which includes sanitization and escaping of the 'start' and 'end' GET parameters.