Lucene search

K
cvelistWPScanCVELIST:CVE-2023-1400
HistoryMar 27, 2023 - 3:37 p.m.

CVE-2023-1400 Modern Events Calendar lite < 6.5.2 - Admin+ Stored XSS

2023-03-2715:37:25
WPScan
www.cve.org
cve-2023-1400
modern events calendar lite
stored xss
wordpress
plugin
settings
high privilege user
cross-site scripting
unfiltered html
multisite setup

0.001 Low

EPSS

Percentile

23.3%

The Modern Events Calendar Lite WordPress plugin before 6.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Modern Events Calendar Lite",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "6.5.2."
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

0.001 Low

EPSS

Percentile

23.3%