Severity
4.8MEDIUM
EPSS
0.3%
top 49.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 5
Latest updateOct 21

Description

The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

18
CVEList
Community Events < 1.5.1 - Admin+ Stored XSS2024-08-05
GHSA
GHSA-7vjh-vmrf-m55g: The Community Events WordPress plugin before 12024-08-05
OSV
linux-oem-6.5 vulnerabilities2024-08-02
OSV
linux-aws, linux-aws-5.4, linux-iot vulnerabilities2024-07-23
OSV
linux-aws-6.5, linux-lowlatency-hwe-6.5, linux-oracle-6.5, linux-starfive-6.5 vulnerabilities2024-07-19

📋Vendor Advisories

2
Red Hat
kernel: aoe: fix the potential use-after-free problem in more places2024-10-21
Red Hat
kernel: aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts2024-04-17
CVE-2024-6270 (MEDIUM CVSS 4.8) | The Community Events WordPress plug | cvebase.io