Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Varun Thorat

#19420of 53,633
13.6Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-13707
8.8
2022-09-16
WordPress · Mobile Events Manager · CVE-2022-1194
**Name of the Vulnerable Software and Affected Versions** Mobile Events Manager WordPress plugin versions prior to 1.4.8 **Description** The issue arises from the improper escaping of the `Enquiry source` field when exporting events and the `Paid for` field when exporting transactions as CSV, leading to a CSV injection vulnerability. **Recommendations** For versions prior to 1.4.8, update to version 1.4.8 or later to resolve the issue. As a temporary workaround, consider avoiding the export of events and transactions as CSV until the update is applied.
PT-2022-9605
4.8
2022-01-24
WordPress · Mobile Events Manager · CVE-2021-25049
**Name of the Vulnerable Software and Affected Versions** Mobile Events Manager WordPress plugin versions prior to 1.4.4 **Description** The issue allows high privilege users to perform Cross-Site Scripting attacks due to the lack of sanitization and escaping of various settings, even when the unfiltered html capability is disallowed. **Recommendations** For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings for high privilege users until the update is applied.