ZeroHour

CVE-2026-84848

niche

Unauthenticated XSS in WordPress Quick Event Manager plugin (<= 9.17)

CVSS 3.1
7.1 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-84848 is an unauthenticated cross-site scripting (XSS) flaw in the Quick Event Manager WordPress plugin, affecting all versions up to and including 9.17. An attacker with no account on the site can submit crafted input that the plugin renders on event-related pages, causing malicious JavaScript to execute in the browser of any visitor or administrator who views the affected content. Successful exploitation could let the attacker redirect users, inject arbitrary content into pages, or perform actions in a victim's browser session; the CVSS 7.1 score reflects low confidentiality/integrity impact with a changed scope and no privileges required. Any WordPress site running Quick Event Manager version 9.17 or earlier is affected. No public proof-of-concept or in-the-wild exploitation is known, and EPSS estimates only a 0.1% probability of exploitation within the next 30 days.

What to do: Update Quick Event Manager to the latest release (any version above 9.17); given no known PoC or exploitation, routine patch prioritization is sufficient. If an immediate update is not possible, consider deactivating the plugin until a patched version is deployed, and review existing events and pages for unexpectedly injected scripts or markup.

Affected
fullworksplugins Quick Event Manager (WordPress plugin)<= 9.17
Estimated exposure
niche~ a few thousand sites (roughly 2,000+ active installs per the WordPress.org directory) — Estimated from the plugin's publicly listed active-install count on the WordPress.org directory, which places the deployed base in the low thousands of sites; this is an estimate, as the source data did not include install counts.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.