CVE-2018-13137: XSS
Published Apr 12, 2019
·Updated
The Events Manager plugin 5.9.4 for WordPress has XSS via the dbemeventreapprovedemailbody parameter to the wp-admin/edit.php?posttype=event&page=events-manager-options URI.
Affected Software
2 affected components
Pixelite Events Manager Wordpress=5.9.4
Wp-events-plugin Events Manager Wordpress=5.9.4
Event History
Apr 12, 2019
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
Description
Frequently Asked Questions
1
What is CVE-2018-13137?
CVE-2018-13137 is a vulnerability in the Events Manager plugin 5.9.4 for WordPress.
2
What is the severity of CVE-2018-13137?
CVE-2018-13137 has a severity rating of medium with a CVSS score of 4.8.
3
How does CVE-2018-13137 affect WordPress?
CVE-2018-13137 affects WordPress through the Events Manager plugin version 5.9.4.
4
What is the CWE category of CVE-2018-13137?
CVE-2018-13137 falls under the CWE category 79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
Is there a fix available for CVE-2018-13137?
Yes, a fix for CVE-2018-13137 is available. It is recommended to update to the latest version of the Events Manager plugin to mitigate the vulnerability.