CVE-2024-8493: The Events Calendar < 6.6.4 - Admin+ Stored XSS
The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8493?
CVE-2024-8493 has a severity rating that indicates it poses a risk of Stored Cross-Site Scripting attacks due to insufficient sanitization.
How do I fix CVE-2024-8493?
To fix CVE-2024-8493, update the Events Calendar WordPress plugin to version 6.6.4 or later.
Who is affected by CVE-2024-8493?
CVE-2024-8493 affects instances of the Events Calendar WordPress plugin prior to version 6.6.4, particularly in environments where high privilege users, like admins, can exploit the vulnerability.
What kind of attacks can CVE-2024-8493 allow?
CVE-2024-8493 can allow high privilege users to execute Stored Cross-Site Scripting attacks.
Is CVE-2024-8493 relevant to multisite WordPress installations?
Yes, CVE-2024-8493 is particularly relevant to multisite WordPress installations where unfiltered_html capability is disallowed.