First published: Mon Nov 29 2021(Updated: )
The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
The Events Calendar | <2.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24876 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
To fix CVE-2021-24876, upgrade the Registrations for the Events Calendar plugin to version 2.7.5 or later.
CVE-2021-24876 can be exploited to perform reflected cross-site scripting attacks, allowing attackers to execute scripts in the user's browser.
CVE-2021-24876 affects all versions of the Registrations for the Events Calendar plugin prior to 2.7.5.
The main issue with CVE-2021-24876 is that it does not properly escape the v parameter, which can lead to reflected cross-site scripting vulnerabilities.