WordPress Plugin Vulnerabilities

Events Made Easy < 1.5.50 - Multi CSRF to Stored Cross-Site Scripting & Event Deletion

Description

The plugin was missing CSRF check in some actions, as well as sanitisation, allowing attacker to make logged in admin create Template and Form Field with Cross-Site Scripting payloads in them, as well as delete arbitrary events.

Proof of Concept

Affects Plugins

Fixed in 1.5.50

References

Miscellaneous

Submitter
ethicalhack3r
Submitter twitter
Verified
No

Timeline

Publicly Published
2015-10-15 (about 10 years ago)
Added
2015-10-16 (about 10 years ago)
Last Updated
2021-10-01 (about 4 years ago)

Other