CVE-2021-24498
MEDIUM EXPLOITED NUCLEIDwbooster Calendar Event Multi View < 1.4.01 - XSS
Title source: ruleDescription
The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.
Nuclei Templates (1)
WordPress Calendar Event Multi View <1.4.01 - Cross-Site Scripting
MEDIUMby suman_kar
Scores
CVSS v3
6.1
EPSS
0.2548
EPSS Percentile
96.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
VulnCheck KEV
2025-06-08
CWE
CWE-79
Status
published
Products (1)
dwbooster/calendar_event_multi_view
< 1.4.01
Published
Aug 02, 2021
Tracked Since
Feb 18, 2026