Modern Events Calendar Lite < 5.22.3 - Authenticated Stored Cross Site Scripting
CVE-2021-24716
5.4MEDIUM
Summary
The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust settings withing wp-admin.
Affected Version(s)
Modern Events Calendar Lite 5.22.3
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Shivam Rai