S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24510 Scanner

CVE-2021-24510 scanner - Cross-Site Scripting (XSS) vulnerability in MF Gig Calendar plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24510
6.1
CVSS

The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back in the admin dashboard when editing an Event, leading to a reflected Cross-Site Scripting issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
MF Gig Calendar
AFFECTED< 1.2SAFE ✓≥ 1.2
Updated Aug 21, 2026View on NVD →
Detail

The MF Gig Calendar plugin is a popular tool used by WordPress website owners to display a calendar of musical events for their audience. This plugin is designed to help musicians and event promoters add and manage events on their website, providing a user-friendly interface for updating the calendar. With its easy-to-use interface and customizable options, the MF Gig Calendar plugin has become a go-to solution for event management on WordPress websites.

However, the plugin is not without its flaws. Recently, a significant vulnerability has been identified in the MF Gig Calendar plugin, labeled CVE-2021-24510. The vulnerability is related to the handling of the id GET parameter, which is not properly sanitized or escaped before being output in the admin dashboard when editing an event. This oversight leaves the plugin open to a reflected Cross-Site Scripting (XSS) attack.

If exploited, the CVE-2021-24510 vulnerability can allow an attacker to inject malicious code into the website and potentially compromise user data. By sending a specially crafted link to an unsuspecting user, a hacker could execute the script within the website and steal sensitive data such as login credentials and personal information. This vulnerability poses a significant risk to any website running the MF Gig Calendar plugin and should be addressed immediately.

In conclusion, the MF Gig Calendar plugin is a useful tool for event management on WordPress websites, but it is not without its vulnerabilities. The CVE-2021-24510 vulnerability poses a significant risk to website owners who use this plugin, leaving them open to XSS attacks and potential data theft. Taking the necessary precautions to protect against this vulnerability is critical for maintaining the integrity and security of any website. With the pro features of s4e.io, website owners can quickly and easily learn about vulnerabilities in their digital assets and take the necessary steps to keep their websites secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners can take the following precautions:

  • Immediately update to the latest version of the MF Gig Calendar plugin (v1.2 or later), which addresses the CVE-2021-24510 vulnerability.
  • Periodically scan your website with a vulnerability scanner to detect any possible exploits.
  • Ensure that all web applications and plugins are kept up-to-date with the latest security patches.
  • Implement strong password policies for all users to prevent unwanted access to the website.
  • Deploy a comprehensive web application firewall (WAF) solution to monitor web traffic and prevent any malicious requests from reaching the website.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24510 scanner - Cross-Site Scripting (XSS) vulnerability in MF Gig Calendar plugin for WordPress | S4E