Community Event < 1.4.8 - Reflected Cross-Site Scripting (XSS)
CVE-2021-24496

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
2 August 2021

Summary

The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator

Affected Version(s)

Community Events 1.4.8

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iohex
.