WordPress Quick Event Manager Plugin <= 9.7.4 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-23979
7.1HIGH
What is CVE-2023-23979?
A stored Cross-Site Scripting (XSS) vulnerability exists in the Fullworks Quick Event Manager plugin. This weakness allows attackers to inject malicious scripts into a web page, which can then be executed by users who view the affected page. If exploited, this can lead to unauthorized actions being performed in the context of the user's session, compromising sensitive user data and potentially leading to further attacks on the website. Users are advised to upgrade to the patched version to mitigate this risk.
Affected Version(s)
Quick Event Manager <= 9.7.4