CVE-2015-9297: XSS
Published Aug 13, 2019
·Updated
The events-manager plugin before 5.6 for WordPress has XSS.
Affected Software
2 affected components
Pixelite Events Manager Wordpress<5.6
Wp-events-plugin Events Manager Wordpress<5.6
Event History
Aug 13, 2019
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
Description
Frequently Asked Questions
1
What is CVE-2015-9297?
CVE-2015-9297 is a vulnerability in the events-manager plugin for WordPress version 5.6 and below, which allows for cross-site scripting (XSS) attacks.
2
What is the severity of CVE-2015-9297?
The severity of CVE-2015-9297 is medium, with a severity value of 6.1.
3
How does CVE-2015-9297 impact WordPress?
CVE-2015-9297 allows an attacker to inject malicious scripts into the events-manager plugin, potentially leading to unauthorized data disclosure or manipulation on a WordPress site.
4
Is there a fix available for CVE-2015-9297?
Yes, updating the events-manager plugin to version 5.6 or higher will fix the vulnerability.
5
Where can I find more information about CVE-2015-9297?
You can find more information about CVE-2015-9297 on the WordPress plugin page for events-manager and the WPScan vulnerability database.