WP Event Manager < 3.1.28 - Reflected Cross-Site Scripting
CVE-2022-1474
6.1MEDIUM
What is CVE-2022-1474?
The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting
Affected Version(s)
WP Event Manager – Easily Build your Calendar of Events! 3.1.28