First published: Tue Mar 25 2025(Updated: )
The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
The Events Calendar | <2.13.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10703 is classified as a high severity vulnerability due to its potential for stored Cross-Site Scripting attacks.
To fix CVE-2024-10703, you should update the Registrations for The Events Calendar plugin to version 2.13.4 or later.
CVE-2024-10703 affects users of the Registrations for The Events Calendar plugin prior to version 2.13.4, particularly those with admin privileges.
CVE-2024-10703 is a stored Cross-Site Scripting vulnerability that arises from improper sanitization and escaping of plugin settings.
Yes, CVE-2024-10703 can be exploited by high privilege users even when the unfiltered_html capability is disallowed.