CVE-2021-24810: WP Event Manager < 3.1.23 - Admin+ Stored Cross-Site Scripting
Published Mar 7, 2022
·Updated
The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed
Affected Software
1 affected component
Wp-eventmanager Wp Event Manager Wordpress<3.1.23
Event History
Mar 7, 2022
CVE Published
via MITRE·08:16 AM
Data Sourced
via MITRE·08:16 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-24810.
2
What is the severity of CVE-2021-24810?
CVE-2021-24810 has a severity level of medium (4.8).
3
What is the affected software?
The affected software is the WP Event Manager WordPress plugin version up to 3.1.23.
4
What is the impact of this vulnerability?
This vulnerability can allow high privilege users to perform Cross-Site Scripting (XSS) attacks.
5
How can the vulnerability be fixed?
To fix this vulnerability, it is recommended to update the WP Event Manager WordPress plugin to version 3.1.23 or later.