CVE-2024-2842
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 29, 2024
CWE ID 89
Summary
CVE-2024-2842 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the Easy Appointments plugin for WordPress. This issue, present in versions up to 3.11.18, stems from insufficient sanitization and output escaping on user-supplied attributes within the 'ea_full_calendar' shortcode. Authenticated attackers with contributor-level access or higher can exploit this weakness by injecting arbitrary web scripts. These scripts will execute whenever an unsuspecting user accesses an affected page, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share