First published: Tue Jun 04 2024(Updated: )
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
The Events Calendar | <6.4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4180 has been classified with a severity rating that indicates it poses a potential risk to affected systems due to improper sanitization of user input.
To fix CVE-2024-4180, update the The Events Calendar plugin to version 6.4.0.1 or later, which includes the necessary security patches.
CVE-2024-4180 affects The Events Calendar WordPress plugin versions prior to 6.4.0.1.
CVE-2024-4180 is a cross-site scripting (XSS) vulnerability due to improper sanitization of user-submitted content.
Yes, CVE-2024-4180 can be exploited by an attacker to execute malicious scripts in a user's browser via AJAX calls.