Vulnerability CVE-2018-9020


Published: 2018-03-25   Modified: 2018-03-26

Description:
The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.

See advisories in our WLB2 database:
Topic
Author
Date
Low
WordPress Event Manager 5.8.1.1 Cross Site Scripting
Luigi Gubello
27.03.2018

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

CVSS2 => (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.5/10
2.9/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None

 References:
http://wp-events-plugin.com/blog/2018/01/15/events-manager-5-8-1-2-security-release/
https://wordpress.org/plugins/events-manager/#developers
https://www.gubello.me/blog/events-manager-authenticated-stored-xss/
https://www.youtube.com/watch?v=40d7uXl36O4

Copyright 2024, cxsecurity.com

 

Back to Top