PT-2024-26948 · WordPress · Easyevent

M3Hd22

+2

·

Published

2024-05-07

·

Updated

2025-05-09

·

CVE-2024-3628

CVSS v3.1

3.8

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions EasyEvent WordPress plugin versions 1.0.0 and earlier
Description The issue allows high privilege users, such as admins, to perform Cross-Site Scripting attacks, even when unfiltered html is disallowed, due to the plugin not sanitizing and escaping some of its settings.
Recommendations For EasyEvent WordPress plugin versions 1.0.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-3628

Affected Products

Easyevent