PT-2022-18637 · WordPress · Modern Events Calendar Lite
Muhammad Daffa
·
Published
2022-04-14
·
Updated
2022-04-22
·
CVE-2022-27848
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Modern Events Calendar Lite (WordPress plugin) versions <= 6.5.1
Description
The issue is related to an Authenticated Stored Cross-Site Scripting (XSS) in the Modern Events Calendar Lite WordPress plugin. This allows an attacker with admin or higher privileges to store malicious scripts that can be executed when other users access the affected system.
Recommendations
For Modern Events Calendar Lite (WordPress plugin) versions <= 6.5.1, update to a version greater than 6.5.1 to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Modern Events Calendar Lite