Description
WordPress Plugin Events Manager is prone to multiple vulnerabilities, including cross-site scripting and code injection vulnerabilities. Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to steal cookie-based authentication credentials or to execute arbitrary code within the context of the affected webserver process, which may result in total compromise of the web server. WordPress Plugin Events Manager version 5.5.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.6 or latest
References
Related Vulnerabilities
Joomla! Core 1.0.x SQL Injection (1.0.0 - 1.0.11)
WordPress Plugin PDF & Print by BestWebSoft Cross-Site Scripting (2.0.2)
MODX Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-26149)
Atlassian Jira CVE-2021-26081 Vulnerability (CVE-2021-26081)
WordPress Plugin FV Flowplayer Video Player URL Cross-Site Scripting (1.2.11)