CVE-2024-6711: Event Tickets with Ticket Scanner < 2.3.8 - Admin+ Stored XSS
The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6711?
CVE-2024-6711 has a severity rating that indicates significant risk due to the potential for Cross-Site Scripting attacks.
How do I fix CVE-2024-6711?
To fix CVE-2024-6711, upgrade the Event Tickets with Ticket Scanner plugin to version 2.3.8 or later.
Who is affected by CVE-2024-6711?
Any user with administrative privileges on a WordPress site using versions of the Event Tickets with Ticket Scanner plugin prior to 2.3.8 is affected.
What kind of attack does CVE-2024-6711 enable?
CVE-2024-6711 enables Cross-Site Scripting (XSS) attacks, which can lead to unauthorized actions on behalf of users.
What specific version of the product is affected by CVE-2024-6711?
CVE-2024-6711 affects all versions of the Event Tickets with Ticket Scanner plugin before version 2.3.8.