CVE-2024-6270: Community Events < 1.5.1 - Admin+ Stored XSS
The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6270?
CVE-2024-6270 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-6270?
To fix CVE-2024-6270, update the Community Events plugin to version 1.5.1 or later.
Who is affected by CVE-2024-6270?
CVE-2024-6270 affects users of the Community Events WordPress plugin versions prior to 1.5.1.
What types of attacks can result from CVE-2024-6270?
CVE-2024-6270 can lead to Stored Cross-Site Scripting attacks, allowing attackers to execute malicious scripts.
What are the potential impacts of exploiting CVE-2024-6270?
Exploiting CVE-2024-6270 could allow attackers to gain unauthorized access and perform harmful actions within a WordPress site.