VulnerabilityModified
CVE-2021-24724
The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the…
MEDIUM 5.4EPSS 0.89%
Does this matter?
Lower severity and a low EPSS score (0.89%). Track it; it rarely justifies an emergency change on its own.
Description
The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the related event/s
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.89% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- motopress/timetable and event schedule
- Source
- contact@wpscan.com
References
- https://plugins.trac.wordpress.org/changeset/2573479/Third Party Advisory
- https://wpscan.com/vulnerability/c1194a1e-bf33-4f3f-a4a6-27b76b1b1eebExploit, Third Party Advisory
- https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29235Exploit, Third Party Advisory
- https://plugins.trac.wordpress.org/changeset/2573479/Third Party Advisory
- https://wpscan.com/vulnerability/c1194a1e-bf33-4f3f-a4a6-27b76b1b1eebExploit, Third Party Advisory
- https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29235Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.