Record summary

CVE-2024-4180 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

The Events Calendar

Default status: unaffected

CVE ListBefore 6.4.0.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMThe Events Calendar < 6.4.0.1 - Cross-site ScriptingCVSS 9.1

The Events Calendar WordPress plugin < 6.4.0.1 contains a stored XSS caused by improper sanitization of user-submitted content when rendering views via AJAX, letting attackers execute scripts in the context of the affected site. Exploitation requires user interaction.

Impact

Attackers can execute arbitrary scripts in the context of the affected site, leading to potential session hijacking or defacement.

Remediation

Update to version 6.4.0.1 or later.

WeaknessesCWE-79
Authors0x_Akoko
Template tagscvecve2024wordpresswp-pluginwpwpscanthe-events-calendarxss
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CPE: cpe:2.3:a:stellarwp:the_events_calendar:*:*:*:*:*:wordpress:*:*
FOFA: body="wp-content/plugins/the-events-calendar/"

Source: ProjectDiscovery

References

2