PT-2020-6390 · WordPress · Event Espresso Core
Published
2020-08-03
·
Updated
2021-07-15
·
CVE-2020-26153
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Event Espresso Core plugin versions prior to 4.10.7.p
Description
A cross-site scripting (XSS) issue exists due to insufficient protection of the web page structure. This allows remote attackers to inject arbitrary web script or HTML via the
page parameter. The vulnerability can be exploited by a remote attacker using a specially crafted GET request.Recommendations
For versions prior to 4.10.7.p, update to version 4.10.7.p or later to resolve the issue. As a temporary workaround, consider restricting access to the
ee msg admin overview.template.php template to minimize the risk of exploitation. Avoid using the page parameter in affected API endpoints until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Event Espresso Core