CVE-2022-1474: WP Event Manager < 3.1.28 - Reflected Cross-Site Scripting
The WP Event Manager WordPress plugin before 3.1.28 does not sanitise and escape its search before outputting it back in an attribute on the event dashboard, leading to a Reflected Cross-Site Scripting
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1474?
CVE-2022-1474 is a vulnerability in the WP Event Manager WordPress plugin before version 3.1.28 that allows for Reflected Cross-Site Scripting (XSS).
How does CVE-2022-1474 affect the WP Event Manager plugin?
CVE-2022-1474 affects the WP Event Manager plugin by not properly sanitizing and escaping the search input, leading to a potential XSS attack.
What is the severity of CVE-2022-1474?
The severity of CVE-2022-1474 is rated as medium with a CVSS score of 6.1.
Is there a fix available for CVE-2022-1474?
Yes, upgrading to version 3.1.28 of the WP Event Manager plugin will fix CVE-2022-1474.
Where can I find more information about CVE-2022-1474?
You can find more information about CVE-2022-1474 at the following reference: https://wpscan.com/vulnerability/2d821464-c502-4f71-afee-97b3dea16612