CVE · Medium

CVE-2019-16523 — Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-16523 Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 5.9.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 5.9.6 5.9.6 2019-10-16

CVE-2019-16523

The Events Manager plugin before version 5.9.6 contains a stored cross-site scripting vulnerability in its shortcode implementation. The map_style attribute used in both the locations_map and events_map shortcodes fails to properly sanitize user-supplied input before storing and displaying it. An attacker could inject malicious scripts through these parameters that would execute in the browsers of website visitors viewing pages containing the affected shortcodes.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.