First published: Mon Jan 24 2022(Updated: )
The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
The Events Calendar | <=2.7.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25083 has a medium severity rating due to its potential for reflected cross-site scripting attacks.
To fix CVE-2021-25083, update the Registrations for the Events Calendar plugin to version 2.7.10 or later.
CVE-2021-25083 affects any WordPress site that uses the Registrations for the Events Calendar plugin versions prior to 2.7.10.
CVE-2021-25083 is associated with reflected cross-site scripting (XSS) attacks.
Yes, CVE-2021-25083 can be easily exploited if an attacker can trick a victim into clicking a manipulated URL.