Record summary

CVE-2021-24876 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 27, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Registrations for the Events Calendar – Event Registration Plugin

CVE List2.7.5 to < 2.7.5affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMRegistrations for The Events Calendar < 2.7.5 - Authenticated Reflected Cross-Site ScriptingCVSS 6.1

The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

Impact

Attackers can inject malicious JavaScript via reflected XSS, potentially stealing administrator session cookies or performing administrative actions on behalf of authenticated users.

Remediation

Fixed in 2.7.5

WeaknessesCWE-79
Authorspopcorn94
Template tagscvecve2021wordpresswpscanwp-pluginwpregistrations-for-the-events-calendarxssauthenticatedvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:roundupwp:registrations_for_the_events_calendar:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/registrations-for-the-events-calendar/"

Source: ProjectDiscovery

References

2