CVE · Medium

CVE-2015-9299 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.7.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2015-9299 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.5.7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.5.7.1 5.5.7.1 2015-06-04

CVE-2015-9299

The Events Manager plugin before version 5.5.7.1 contains a DOM-based cross-site scripting vulnerability that can be exploited through the dbem_event_reapproved_email_body parameter. An attacker could inject malicious scripts via this parameter, which would execute in users' browsers when the affected code is processed. This vulnerability affects all versions prior to 5.5.7.1 and was resolved in that release.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.