CVE-2024-4180
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering some views via AJAX.
- Affected products
- The Events Calendar
- Stellarwp The Events Calendar
- < 6.4.0.1
- Fix
- Available
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 1.8% (78th percentile)
- Weakness
- CWE-79
- NVD status
- Analyzed
- Published
- 2024-06-04
CVE-2024-4180 at NVD
1 known exploit for CVE-2024-4180
Proof-of-concept code and exploit modules indexed by Sploitus