Description

WordPress Plugin Events Manager is prone to multiple vulnerabilities, including cross-site scripting and code injection vulnerabilities. Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, to steal cookie-based authentication credentials or to execute arbitrary code within the context of the affected webserver process, which may result in total compromise of the web server. WordPress Plugin Events Manager version 5.5.7.1 is vulnerable; prior versions may also be affected.

Remediation

Update to plugin version 5.6 or latest

References

Related Vulnerabilities