Reflected Cross-Site Scripting in Events Manager Plugin for WordPress
CVE-2026-17089

6.1MEDIUM

What is CVE-2026-17089?

The Events Manager plugin for WordPress is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability due to inadequate input validation and output escaping. This flaw exists in all versions up to 7.4.0.1, where the 'header_format' parameter can be manipulated via an unauthenticated AJAX action. Attackers can exploit this vulnerability to inject malicious scripts into web pages, which may run if a victim clicks a specially-crafted link. The existing sanitation method (wp_kses()) fails in some contexts, enabling unsanitized outputs leading to security risks.

Affected Version(s)

Events Manager – Calendar, Bookings, Tickets, and more! 0 <= 7.4.0.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.