Persistent XSS in RSVP Plugin for WordPress by Rsvp
CVE-2017-18563
6.1MEDIUM
What is CVE-2017-18563?
The RSVP plugin prior to version 2.3.8 for WordPress contains a persistent XSS vulnerability that can be exploited through the note field on the attendee-list screen. Attackers can inject malicious scripts into this field, which may execute in the browsers of users viewing the list, creating potential for data theft and account compromise.