PT-2026-81165 · WordPress · Events Manager
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Events Manager – Calendar, Bookings, Tickets, and more! versions prior to 7.4.0.2
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Reflected Cross-Site Scripting (XSS). This occurs when the
search events grouped AJAX action bypasses sanitization for the header format parameter before it is processed by the output grouped() function and echoed into the HTML body. An attacker can exploit this by tricking a user into clicking a malicious link to execute arbitrary web scripts in their browser.Recommendations
Update to version 7.4.0.2 or later.
As a temporary mitigation, restrict access to the
search events grouped AJAX action or avoid using the header format parameter.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Events Manager