ZeroHour

CVE-2023-5238

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p36
Published
()
Modified
Description

The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injection on the plugin in the search area of the website.

Vendors
metagauss
Products
eventprime
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.