PublicCVE

CVE-2022-0364

UNRATED
High EPSS
JSON exportCreate alert

Description

The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule parameters which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

Affected products