CVE-2022-46863: WordPress Quick Event Manager Plugin <= 9.6.4 is vulnerable to Cross Site Scripting (XSS)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.6.4 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-46863?
CVE-2022-46863 is an authentication bypass vulnerability in the Fullworks Quick Event Manager plugin for Wordpress.
How does CVE-2022-46863 impact my website?
CVE-2022-46863 allows an attacker with admin+ privileges to store malicious script code on your website, potentially leading to cross-site scripting (XSS) attacks.
What is the severity of CVE-2022-46863?
CVE-2022-46863 has a severity rating of medium, with a CVSS score of 4.8.
How do I fix CVE-2022-46863?
To fix CVE-2022-46863, you should update the Fullworks Quick Event Manager plugin to version 9.6.5 or later.
Where can I find more information about CVE-2022-46863?
You can find more information about CVE-2022-46863 on the Patchstack website: [Link](https://patchstack.com/database/vulnerability/quick-event-manager/wordpress-quick-event-manager-plugin-9-6-4-cross-site-scripting-xss?_s_id=cve)