First published: Wed Aug 21 2019(Updated: )
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
The Events Calendar | <4.8.2 | |
The Events Calendar | <4.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15109 is classified as a medium severity vulnerability due to its potential for exploiting cross-site scripting (XSS).
To fix CVE-2019-15109, upgrade the The Events Calendar plugin to version 4.8.2 or later immediately.
CVE-2019-15109 affects users of The Events Calendar plugin for WordPress prior to version 4.8.2.
CVE-2019-15109 can be exploited through XSS attacks, allowing attackers to inject malicious scripts into web pages viewed by users.
You can determine if your site is vulnerable to CVE-2019-15109 by checking the version of The Events Calendar plugin; any version below 4.8.2 is vulnerable.