Description
The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-11958 | The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS. |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:49:14.633Z
Reserved: 2021-01-14T00:00:00.000Z
Link: CVE-2021-25046
No data.
Status : Modified
Published: 2022-01-17T13:15:07.967
Modified: 2024-11-21T05:54:14.977
Link: CVE-2021-25046
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD