First published: Tue Aug 18 2015(Updated: )
Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
The Events Calendar | <=3.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5485 is considered a high severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2015-5485, update the Modern Tribe Eventbrite Tickets plugin to version 3.10.2 or later.
CVE-2015-5485 facilitates remote attackers to perform cross-site scripting (XSS) attacks through the Event Import page.
CVE-2015-5485 affects the Modern Tribe Eventbrite Tickets plugin versions prior to 3.10.2.
CVE-2015-5485 can be exploited on the Event Import page of the affected WordPress site.