CVE-2021-24496

Severity
6.1MEDIUM
EPSS
0.2%
top 59.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 2
Latest updateMay 24

Description

The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-9g3p-ghhv-vpv9: The Community Events WordPress plugin before 12022-05-24
CVEList
Community Event < 1.4.8 - Reflected Cross-Site Scripting (XSS)2021-08-02
CVE-2021-24496 (MEDIUM CVSS 6.1) | The Community Events WordPress plug | cvebase.io