Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Modern Events Calendar Lite < 6.2.0 - Subscriber+ Category Add Leading to Stored XSS
Vulnerability Description
The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
WordPress plugin 跨站脚本漏洞
Vulnerability Description
WordPress plugin是WordPress开源的一个应用插件。 WordPress plugin的Modern Events Calendar Lite 插件6.2.0之前版本存在跨站脚本漏洞,该漏洞源于参数在管理面板中被错误转义,攻击者可利用该漏洞执行XSS攻击。
CVSS Information
N/A
Vulnerability Type
N/A