CVE-2013-7478: XSS
Published Aug 22, 2019
·Updated
The events-manager plugin before 5.5 for WordPress has XSS via EMTicket::getpost.
Affected Software
2 affected components
Pixelite Events Manager Wordpress<5.5
Wp-events-plugin Events Manager Wordpress<5.5
Event History
Aug 22, 2019
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2013-7478.
2
What is the title of this vulnerability?
The title of this vulnerability is 'The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.'
3
What is the severity rating of CVE-2013-7478?
CVE-2013-7478 has a severity rating of 6.1 (medium).
4
How does the events-manager plugin before 5.5 for WordPress get exploited?
The events-manager plugin before 5.5 for WordPress is exploited through XSS (Cross-Site Scripting) using the EM_Ticket::get_post method.
5
How can I fix the events-manager plugin before 5.5 for WordPress vulnerability?
To fix the vulnerability, update the events-manager plugin to version 5.5 or later.