WordPress Quick Event Manager Plugin <= 9.7.4 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-23979

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 April 2023

What is CVE-2023-23979?

A stored Cross-Site Scripting (XSS) vulnerability exists in the Fullworks Quick Event Manager plugin. This weakness allows attackers to inject malicious scripts into a web page, which can then be executed by users who view the affected page. If exploited, this can lead to unauthorized actions being performed in the context of the user's session, compromising sensitive user data and potentially leading to further attacks on the website. Users are advised to upgrade to the patched version to mitigate this risk.

Affected Version(s)

Quick Event Manager <= 9.7.4

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yuyudhn (Patchstack Alliance)
.