CVE-2015-5485: XSS
Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5485?
CVE-2015-5485 is considered a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2015-5485?
To fix CVE-2015-5485, update the Modern Tribe Eventbrite Tickets plugin to version 3.10.2 or later.
What kind of attack does CVE-2015-5485 facilitate?
CVE-2015-5485 facilitates remote attackers to perform cross-site scripting (XSS) attacks through the Event Import page.
What versions of the plugin are affected by CVE-2015-5485?
CVE-2015-5485 affects the Modern Tribe Eventbrite Tickets plugin versions prior to 3.10.2.
Where can CVE-2015-5485 be exploited?
CVE-2015-5485 can be exploited on the Event Import page of the affected WordPress site.