CVE-2021-24510

MEDIUM NUCLEI

MF Gig Calendar < 1.1 - XSS

Title source: rule

Description

The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue

Nuclei Templates (1)

WordPress MF Gig Calendar <=1.1 - Cross-Site Scripting
MEDIUMby dhiyaneshDK

Scores

CVSS v3 6.1
EPSS 0.2115
EPSS Percentile 95.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

Status published
Products (1)
mf_gig_calendar_project/mf_gig_calendar < 1.1
Published Sep 13, 2021
Tracked Since Feb 18, 2026