WordPress Plugin Vulnerabilities

Event Espresso Core < 4.10.7.p - Reflected Cross-Site Scripting (XSS)

Description

The admin_pages/messages/templates/ee_msg_admin_overview.template.php file of the plugin did not escape user input before outputting back in an attribute in the page, leading to a reflected Cross-Site Scripting issue

Proof of Concept

Affects Plugins

Fixed in 4.10.7.p

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Nettitude
Verified
Yes

Timeline

Publicly Published
2021-06-25 (about 4 years ago)
Added
2021-07-13 (about 4 years ago)
Last Updated
2021-08-10 (about 4 years ago)

Other