ZeroHour

CVE-2022-1474

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p56
Published
()
Modified
Description

The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting

Vendors
wp-eventmanager
Products
wp event manager
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.