Cross Site Scripting Vulnerability in Quick Event Manager by WordPress
CVE-2026-84848

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 September 2026

What is CVE-2026-84848?

An unauthenticated Cross Site Scripting (XSS) vulnerability exists in Quick Event Manager versions up to 9.17. This flaw may allow attackers to inject malicious scripts, potentially compromising user interactions with the application. Exploitation of this vulnerability could lead to unauthorized access to sensitive data or the execution of harmful operations, emphasizing the need for prompt patching and security measures.

Affected Version(s)

Quick Event Manager <= 9.17

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ParkHyunWoo | Patchstack Bug Bounty Program
.