CVE-2024-4180
The Events Calendar < 6.4.0.1 - Reflected XSS
Record summary
CVE-2024-4180 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
The Events CalendarDefault status: unaffected | CVE List | Before 6.4.0.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMThe Events Calendar < 6.4.0.1 - Cross-site ScriptingCVSS 9.1
The Events Calendar WordPress plugin < 6.4.0.1 contains a stored XSS caused by improper sanitization of user-submitted content when rendering views via AJAX, letting attackers execute scripts in the context of the affected site. Exploitation requires user interaction.
Impact
Attackers can execute arbitrary scripts in the context of the affected site, leading to potential session hijacking or defacement.
Remediation
Update to version 6.4.0.1 or later.
Source: ProjectDiscovery