Vulnerabilities > CVE-2021-24480 - Unspecified vulnerability in Event Geek Project Event Geek 2.5.2

047910
CVSS 4.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
event-geek-project

Summary

The Event Geek WordPress plugin through 2.5.2 does not sanitise or escape its "Use your own " setting before outputting it in the page, leading to an authenticated (admin+) stored Cross-Site Scripting issue

Vulnerable Configurations

Part Description Count
Application
Event_Geek_Project
2