{"id":"CVE-2024-7982","details":"The Registrations for the Events Calendar  WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks.","modified":"2026-03-25T19:45:14.455662Z","published":"2024-11-08T06:15:17.470Z","related":["MGASA-2024-0321"],"references":[{"type":"EVIDENCE","url":"https://wpscan.com/vulnerability/d79e1e9c-980d-4974-bfbd-d87d6e28d9a6/"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"2.12.4"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7982.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}