CVE-2023-23491: XSS
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qemajaxcalendar' action.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-23491?
CVE-2023-23491 is a reflected cross-site scripting vulnerability in the Quick Event Manager WordPress Plugin, version less than 9.7.5, specifically in the 'category' parameter of the 'qem_ajax_calendar' action.
How does CVE-2023-23491 affect the Quick Event Manager WordPress Plugin?
CVE-2023-23491 affects version less than 9.7.5 of the Quick Event Manager WordPress Plugin by enabling attackers to execute malicious scripts in a victim's browser.
How severe is CVE-2023-23491?
CVE-2023-23491 has a severity score of 6.1, which is classified as medium.
How do I fix CVE-2023-23491?
To fix CVE-2023-23491, users should update their Quick Event Manager WordPress Plugin to version 9.7.5 or later.
Where can I find more information about CVE-2023-23491?
More information about CVE-2023-23491 can be found at the following reference: [Tenable Security Advisory](https://www.tenable.com/security/research/tra-2023-3).