CVE-2022-30533
Modern Events Calendar Lite <= 6.2.9 - Authenticated (Contributor+) Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting vulnerability in Modern Events Calendar Lite versions prior to 6.3.0 allows remote an authenticated attacker to inject an arbitrary script via unspecified vectors.
Una vulnerabilidad de tipo cross-site scripting en Modern Events Calendar Lite versiones anteriores a 6.3.0, permite a un atacante remoto autenticado inyectar un script arbitrario por medio de vectores no especificados
The Modern Events Calendar Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 6.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-26 CVE Reserved
- 2022-06-01 CVE Published
- 2024-01-06 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://jvn.jp/en/jp/JVN04155116/index.html | Third Party Advisory | |
https://webnus.net/modern-events-calendar/lite | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Webnus Search vendor "Webnus" | Modern Events Calendar Lite Search vendor "Webnus" for product "Modern Events Calendar Lite" | < 6.3.0 Search vendor "Webnus" for product "Modern Events Calendar Lite" and version " < 6.3.0" | wordpress |
Affected
|