First published: Mon Jan 16 2023(Updated: )
The WordPress Events Calendar WordPress plugin before 1.4.5 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against both unauthenticated and authenticated users (such as high-privilege ones like admin).
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mhsoftware Wordpress Events Calendar Plugin | <1.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4320 is a vulnerability in the WordPress Events Calendar WordPress plugin before version 1.4.5 that allows for Reflected Cross-Site Scripting (XSS) attacks.
CVE-2022-4320 affects both unauthenticated and authenticated users, including high-privilege ones like admins, by allowing for potential XSS attacks.
The severity of CVE-2022-4320 is medium with a CVSS score of 6.1.
To fix CVE-2022-4320, upgrade the WordPress Events Calendar plugin to version 1.4.5 or newer.
You can find more information about CVE-2022-4320 at the following reference: https://wpscan.com/vulnerability/f1244c57-d886-4a6e-8cdb-18404e8c153c