ZeroHour

CVE-2021-24498

PoC
CVSS 3.1
6.1 medium
EPSS
4%p89
Published
()
Modified
Description

The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.

Vendors
dwbooster
Products
calendar event multi view
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.