PT-2022-9605 · WordPress · Mobile Events Manager

Varun Thorat

·

Published

2022-01-24

·

Updated

2022-09-20

·

CVE-2021-25049

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mobile Events Manager WordPress plugin versions prior to 1.4.4
Description The issue allows high privilege users to perform Cross-Site Scripting attacks due to the lack of sanitization and escaping of various settings, even when the unfiltered html capability is disallowed.
Recommendations For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings for high privilege users until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-25049

Affected Products

Mobile Events Manager