First published: Wed Oct 16 2019(Updated: )
The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper encoding and insertion of data provided to the attribute map_style of shortcodes (locations_map and events_map) provided by the plugin.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pixelite Events Manager | <=5.9.5 | |
WP Event Manager | <=5.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-16523.
The affected software is the events-manager plugin for WordPress (aka Events Manager) version up to 5.9.5.
The severity of CVE-2019-16523 is medium.
CVE-2019-16523 allows attackers to execute stored cross-site scripting (XSS) attacks by manipulating the map_style attribute of shortcodes provided by the events-manager plugin.
To fix CVE-2019-16523, update the events-manager plugin to version 5.9.6 or later.