ZeroHour

CVE-2023-1126

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p37
Published
()
Modified
Description

The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks

Vendors
wp fevents book project
Products
wp fevents book
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.