CVE-2024-0614
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Mar 13, 2024
Summary
CVE-2024-0614 is a Stored Cross-Site Scripting vulnerability affecting the Events Manager plugin for WordPress. This issue, present in all versions up to 6.4.6.4, allows authenticated attackers with administrator-level permissions to inject arbitrary web scripts into admin settings. The vulnerable input is not properly sanitized or escaped, resulting in the execution of these scripts whenever a user accesses an injected page. This vulnerability only impacts multi-site installations and installations where unfiltered_html has been disabled.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.