Reflected XSS Vulnerability in WpEvently by MagePeopleTeam
CVE-2026-25361
7.1HIGH
What is CVE-2026-25361?
The WpEvently plugin developed by MagePeopleTeam is vulnerable to a reflected cross-site scripting (XSS) attack due to improper neutralization of input during web page generation. Specifically, this vulnerability affects versions from n/a up to and including 5.1.4, allowing attackers to inject malicious scripts that can be executed in the context of a user's browser. This can lead to unauthorized actions, theft of sensitive data, and compromised user accounts. It is essential for users of the affected versions to implement necessary updates or mitigations to safeguard their systems.
Affected Version(s)
WpEvently <= n/a