First published: Mon Sep 20 2021(Updated: )
The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting them in page/post where the associated shortcode is embed, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Steve Availability Calendar | <1.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-24604.
The affected software is the Availability Calendar WordPress plugin before version 1.2.2.
The severity of CVE-2021-24604 is medium with a CVSS score of 4.8.
This vulnerability allows high privilege users to perform Cross-Site Scripting (XSS) attacks even when the unfiltered_html is disallowed.
Yes, the fix for this vulnerability is to update the Availability Calendar WordPress plugin to version 1.2.2 or newer.