CVE-2021-25083
24.01.2022, 08:15
The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting
Vendor | Product | Version |
---|---|---|
roundupwp | registrations_for_the_events_calendar | 𝑥 ≤ 2.7.10 |
𝑥
= Vulnerable software versions