Reflected Cross-Site Scripting in Events Manager Plugin for WordPress
CVE-2026-17089
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-17089?
The Events Manager plugin for WordPress is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability due to inadequate input validation and output escaping. This flaw exists in all versions up to 7.4.0.1, where the 'header_format' parameter can be manipulated via an unauthenticated AJAX action. Attackers can exploit this vulnerability to inject malicious scripts into web pages, which may run if a victim clicks a specially-crafted link. The existing sanitation method (wp_kses()) fails in some contexts, enabling unsanitized outputs leading to security risks.
Affected Version(s)
Events Manager β Calendar, Bookings, Tickets, and more! 0 <= 7.4.0.1