CVE-2022-25612: WordPress Simple Event Planner plugin <= 1.5.4 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <= 1.5.4 allows user with author or higher user rights inject the malicious code via vulnerable parameters: &custom[eventorganiser], &custom[organiseremail], &custom[organisercontact].
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-25612?
CVE-2022-25612 is a vulnerability that refers to Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in the Simple Event Planner WordPress plugin <= 1.5.4.
What is the severity of CVE-2022-25612?
The severity of CVE-2022-25612 is medium with a CVSSv3 score of 5.4.
Which software is affected by CVE-2022-25612?
The Simple Event Planner WordPress plugin version 1.5.4 and earlier is affected by CVE-2022-25612.
How can an attacker exploit CVE-2022-25612?
An attacker with author or higher user rights can exploit CVE-2022-25612 by injecting malicious code through vulnerable parameters such as &custom[event_organiser], &custom[organiser_email], &custom[organiser_cont].
Are there any patches or fixes available for CVE-2022-25612?
Yes, patches and fixes for CVE-2022-25612 are available. You can find them at the following references: [Patchstack](https://patchstack.com/database/vulnerability/simple-event-planner/wordpress-simple-event-planner-plugin-1-5-4-multiple-authenticated-persistent-cross-site-scripting-xss-vulnerabilities) and the [WordPress Plugin Page](https://wordpress.org/plugins/simple-event-planner/#developers).