The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
Metrics
Affected Vendors & Products
References
History
Fri, 08 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Roundupwp
Roundupwp registrations For The Events Calendar |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:roundupwp:registrations_for_the_events_calendar:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Roundupwp
Roundupwp registrations For The Events Calendar |
|
Metrics |
cvssV3_1
|
Fri, 08 Nov 2024 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks. | |
Title | Registrations for The Events Calendar < 2.12.4 - Unauthenticated Stored XSS | |
References |
|
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-11-08T06:00:03.350Z
Updated: 2024-11-08T14:36:17.779Z
Reserved: 2024-08-19T19:39:32.375Z
Link: CVE-2024-7982
Vulnrichment
Updated: 2024-11-08T14:36:12.269Z
NVD
Status : Awaiting Analysis
Published: 2024-11-08T06:15:17.470
Modified: 2024-11-08T19:01:03.880
Link: CVE-2024-7982
Redhat
No data.