CVE Database /
CVE-2019-16523
CVE · Medium
CVE-2019-16523 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2019-16523
|
Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.6 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 5.9.6
|
5.9.6 |
2019-10-16 |
—
|
CVE-2019-16523
The Events Manager plugin before version 5.9.6 contains a stored cross-site scripting vulnerability in its shortcode implementation. The map_style attribute used in both the locations_map and events_map shortcodes fails to properly sanitize user-supplied input before storing and displaying it. An attacker could inject malicious scripts through these parameters that would execute in the browsers of website visitors viewing pages containing the affected shortcodes.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings