CVE-2026-84848
nicheUnauthenticated XSS in WordPress Quick Event Manager plugin (<= 9.17)
CVE-2026-84848 is an unauthenticated cross-site scripting (XSS) flaw in the Quick Event Manager WordPress plugin, affecting all versions up to and including 9.17. An attacker with no account on the site can submit crafted input that the plugin renders on event-related pages, causing malicious JavaScript to execute in the browser of any visitor or administrator who views the affected content. Successful exploitation could let the attacker redirect users, inject arbitrary content into pages, or perform actions in a victim's browser session; the CVSS 7.1 score reflects low confidentiality/integrity impact with a changed scope and no privileges required. Any WordPress site running Quick Event Manager version 9.17 or earlier is affected. No public proof-of-concept or in-the-wild exploitation is known, and EPSS estimates only a 0.1% probability of exploitation within the next 30 days.
What to do: Update Quick Event Manager to the latest release (any version above 9.17); given no known PoC or exploitation, routine patch prioritization is sufficient. If an immediate update is not possible, consider deactivating the plugin until a patched version is deployed, and review existing events and pages for unexpectedly injected scripts or markup.
| fullworksplugins Quick Event Manager (WordPress plugin) | <= 9.17 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.