Vulnerability Description
The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Roundupwp | Registrations For The Events Calendar | <= 2.7.10 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/2648377PatchThird Party Advisory
- https://wpscan.com/vulnerability/9b69544d-6a08-4757-901b-6ccf1cd00eccExploitThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/2648377PatchThird Party Advisory
- https://wpscan.com/vulnerability/9b69544d-6a08-4757-901b-6ccf1cd00eccExploitThird Party Advisory
FAQ
What is CVE-2021-25083?
CVE-2021-25083 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cros...
How severe is CVE-2021-25083?
CVE-2021-25083 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25083?
Check the references section above for vendor advisories and patch information. Affected products include: Roundupwp Registrations For The Events Calendar.