CVE-2024-10703: Registrations for The Events Calendar < 2.13.4 - Admin+ Stored XSS
The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10703?
CVE-2024-10703 is classified as a high severity vulnerability due to its potential for stored Cross-Site Scripting attacks.
How do I fix CVE-2024-10703?
To fix CVE-2024-10703, you should update the Registrations for The Events Calendar plugin to version 2.13.4 or later.
Who is affected by CVE-2024-10703?
CVE-2024-10703 affects users of the Registrations for The Events Calendar plugin prior to version 2.13.4, particularly those with admin privileges.
What type of vulnerability is CVE-2024-10703?
CVE-2024-10703 is a stored Cross-Site Scripting vulnerability that arises from improper sanitization and escaping of plugin settings.
Can CVE-2024-10703 be exploited without unfiltered_html capability?
Yes, CVE-2024-10703 can be exploited by high privilege users even when the unfiltered_html capability is disallowed.