CVE-2024-8701

Vulnerability Details

Basic Information

Title CVE-2024-8701
Type cve
Published 2025-05-15T20:15:59
Last Seen 2025-05-15T20:24:37
CVSS Score 0.0 ()

CVSS v3 Details

Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact

CVE Information

CVE IDs CVE-2024-8701
CWE
Bulletin Family cve

Description

The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Impact Assessment

Base Score 0.0
Severity

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.