CVE-2020-26153: XSS
A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/adminpages/messages/templates/eemsgadminoverview.template.php in the Event Espresso Core plugin before 4.10.7.p for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26153?
CVE-2020-26153 is classified as a cross-site scripting (XSS) vulnerability which allows remote attackers to inject arbitrary web scripts or HTML.
How do I fix CVE-2020-26153?
To fix CVE-2020-26153, update the Event Espresso Core plugin to version 4.10.7.p or later.
What versions of Event Espresso are affected by CVE-2020-26153?
CVE-2020-26153 affects Event Espresso Core plugin versions prior to 4.10.7.p.
Can CVE-2020-26153 expose user data?
Yes, CVE-2020-26153 can potentially expose user data through malicious scripts injected via the vulnerability.
Is CVE-2020-26153 easy to exploit?
CVE-2020-26153 can be exploited easily by attackers with knowledge of the affected plugin and basic web scripting.