Stored Cross-Site Scripting Vulnerability in The Events Calendar Plugin for WordPress
CVE-2024-12118
6.4MEDIUM
Summary
The Events Calendar plugin for WordPress contains a vulnerability that allows authenticated attackers with Contributor-level access or higher to exploit the Event Calendar Link Widget. This vulnerability arises from inadequate input sanitization and output escaping in the html_tag attribute. By exploiting this flaw, attackers can inject arbitrary web scripts, which are executed when users access the infected pages, potentially compromising user data and site integrity.
Affected Version(s)
The Events Calendar * <= 6.9.0
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
wesley