WordPress WP Event Manager Plugin <= 3.1.39 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-47697
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 November 2023
What is CVE-2023-47697?
A reflected cross-site scripting vulnerability exists in the WP Event Manager plugin versions up to 3.1.39. This vulnerability allows attackers to inject malicious scripts into the response page, potentially compromising user sessions and redirecting users to malicious websites. Attackers can exploit this weakness without authentication, making it imperative for users of the plugin to update to the latest version to mitigate the risk.
Affected Version(s)
WP Event Manager β Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.39