S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24498 Scanner

CVE-2021-24498 scanner - Cross-Site Scripting (XSS) vulnerability in Calendar Event Multi View plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24498
6.1
CVSS

The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Calendar Event Multi View
AFFECTED< 1.4.01SAFE ✓≥ 1.4.01
Updated Aug 21, 2026View on NVD →
Detail

The Calendar Event Multi View plugin for WordPress is a tool designed to manage events through the creation of calendars with various views. This plugin provides users a comprehensive overview of all events, allowing them to easily and effectively manage their schedules. It is widely used by businesses, organizations, and individuals who need to keep track of multiple events happening at a particular time.

A vulnerability detected in the Calendar Event Multi View plugin for WordPress is the CVE-2021-24498. This vulnerability stems from the fact that the plugin does not sanitize or escape the 'start' and 'end' parameters before outputting them in the page, specifically via php/edit.php. This leads to a reflected Cross-Site Scripting issue that could put the security and confidentiality of the user's data at risk.

Exploiting the CVE-2021-24498 vulnerability can lead to serious consequences. Hackers can inject malicious code into the 'start' and 'end' parameters in order to execute attacks on unsuspecting users who access the page. This can result in the hacker gaining access to sensitive data, such as login credentials and payment information, among others. The attack could also affect the functionality of the website and undermine the credibility of the organization.

In conclusion, it is important to remain vigilant and proactive in ensuring the security of digital assets. At s4e.io, we offer advanced security features that provide users with accurate and up-to-date information about vulnerabilities in their digital assets. Our pro features enable users to quickly and easily learn about vulnerabilities in their digital assets, and take steps to mitigate them before they are exploited. With our platform, users can rest assured that they have the tools and support they need to protect their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, several precautions can be taken. These include:

  • Updating the Calendar Event Multi View plugin to its latest version.
  • Implementing a Web Application Firewall (WAF) and ensuring that it is properly configured.
  • Using Content Security Policy (CSP) to prevent XSS attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24498 scanner - Cross-Site Scripting (XSS) vulnerability in Calendar Event Multi View plugin for WordPress | S4E