CVE detail
CVE-2021-24724 — CVE-2021-24724
Published 2021-09-13 · Modified 2026-06-17 · Vendor motopress · Product timetable_and_event_schedule · Source nvd
MEDIUM
severity
CVSS-derived band
0.0089
EPSS probability
exploitation probability, 30d
56.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the related event/s
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References