CVE

CVE-2013-1407 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2013-1407 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.3.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 5.3.5 5.3.5 2013-01-19

CVE-2013-1407

The Events Manager plugin before version 5.3.5 contains multiple cross-site scripting flaws that permit attackers to inject malicious scripts or HTML content through several vectors, including the scope parameter in index.php, user registration fields such as user_name, dbem_phone, user_email, and booking_comment on events with registration active, and the _wpnonce parameter in the WordPress admin edit.php file.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.