The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the related event/s
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:42:16.651Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24724

No data.

Status : Modified
Published: 2021-09-13T18:15:18.243
Modified: 2024-11-21T05:53:38.293
Link: CVE-2021-24724

No data.