First published: Mon Jan 17 2022(Updated: )
The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes, leading to Reflected Cross-SIte Scripting issues
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
The Events Calendar | <1.1.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25024 has a high severity rating due to its potential for reflected Cross-Site Scripting attacks.
To fix CVE-2021-25024, update the EventCalendar WordPress plugin to version 1.1.51 or later.
CVE-2021-25024 affects the EventCalendar WordPress plugin versions prior to 1.1.51.
CVE-2021-25024 is a reflected Cross-Site Scripting vulnerability.
Attackers can exploit CVE-2021-25024 to execute arbitrary scripts in the context of a user's browser.