CVE-2021-25024: Event Calendar < 1.1.51 - Reflected Cross-Site Scripting
Published Jan 17, 2022
·Updated
The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues
Affected Software
1 affected component
Theeventscalendar Eventcalendar Wordpress<1.1.51
Event History
Jan 17, 2022
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25024?
CVE-2021-25024 has a high severity rating due to its potential for reflected Cross-Site Scripting attacks.
2
How do I fix CVE-2021-25024?
To fix CVE-2021-25024, update the EventCalendar WordPress plugin to version 1.1.51 or later.
3
What software is affected by CVE-2021-25024?
CVE-2021-25024 affects the EventCalendar WordPress plugin versions prior to 1.1.51.
4
What kind of vulnerability is CVE-2021-25024?
CVE-2021-25024 is a reflected Cross-Site Scripting vulnerability.
5
What can attackers achieve with CVE-2021-25024?
Attackers can exploit CVE-2021-25024 to execute arbitrary scripts in the context of a user's browser.