WordPress WP Event Manager Plugin <= 3.1.39 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-47697

7.1HIGH

What is CVE-2023-47697?

A reflected cross-site scripting vulnerability exists in the WP Event Manager plugin versions up to 3.1.39. This vulnerability allows attackers to inject malicious scripts into the response page, potentially compromising user sessions and redirecting users to malicious websites. Attackers can exploit this weakness without authentication, making it imperative for users of the plugin to update to the latest version to mitigate the risk.

Affected Version(s)

WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.39

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LEE SE HYOUNG (Patchstack Alliance)
.