The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
History

Fri, 08 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Roundupwp
Roundupwp registrations For The Events Calendar
Weaknesses CWE-79
CPEs cpe:2.3:a:roundupwp:registrations_for_the_events_calendar:*:*:*:*:*:wordpress:*:*
Vendors & Products Roundupwp
Roundupwp registrations For The Events Calendar
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 08 Nov 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
Title Registrations for The Events Calendar < 2.12.4 - Unauthenticated Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-11-08T06:00:03.350Z

Updated: 2024-11-08T14:36:17.779Z

Reserved: 2024-08-19T19:39:32.375Z

Link: CVE-2024-7982

cve-icon Vulnrichment

Updated: 2024-11-08T14:36:12.269Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-08T06:15:17.470

Modified: 2024-11-08T19:01:03.880

Link: CVE-2024-7982

cve-icon Redhat

No data.