Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ansarisec

#21825of 53,632
10.9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2019-8926
4.8
2019-04-12
WordPress · Events Manager · CVE-2018-13137
**Name of the Vulnerable Software and Affected Versions** Events Manager plugin version 5.9.4 **Description** The issue concerns a cross-site scripting (XSS) problem. It is exploited via the `dbem event reapproved email body` parameter to the "wp-admin/edit.php?post type=event&page=events-manager-options" URI. **Recommendations** For Events Manager plugin version 5.9.4, consider disabling access to the `dbem event reapproved email body` parameter in the affected URI until a patch is available. Restrict access to the "wp-admin/edit.php?post type=event&page=events-manager-options" URI to minimize the risk of exploitation.
PT-2018-11625
6.1
2018-07-04
WordPress · Ultimate Member · CVE-2018-13136
**Name of the Vulnerable Software and Affected Versions** The Ultimate Member plugin versions prior to 2.0.18 **Description** The issue allows for XSS via the wp-admin settings screen. **Recommendations** For versions prior to 2.0.18, update to version 2.0.18 or later to resolve the issue.