CVE-2023-33326: WordPress EventPrime Plugin <= 2.8.6 is vulnerable to Cross Site Scripting (XSS)
Unauth. Reflected (XSS) Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 2.8.6 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress EventPrime Pluginto a version that resolves this vulnerability.Fixed in 3.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33326?
The severity of CVE-2023-33326 is high.
What is the affected software of CVE-2023-33326?
The affected software of CVE-2023-33326 is the EventPrime plugin <= 2.8.6 versions.
What is the vulnerability type of CVE-2023-33326?
The vulnerability type of CVE-2023-33326 is Unauth. Reflected (XSS) Cross-Site Scripting (XSS).
How can I fix CVE-2023-33326?
To fix CVE-2023-33326, update the EventPrime plugin to a version greater than 2.8.6.
Is there any additional information about CVE-2023-33326?
Yes, you can find more information about CVE-2023-33326 in the reference link: [https://patchstack.com/database/vulnerability/eventprime-event-calendar-management/wordpress-eventprime-plugin-2-8-6-reflected-cross-site-scripting-xss?_s_id=cve](https://patchstack.com/database/vulnerability/eventprime-event-calendar-management/wordpress-eventprime-plugin-2-8-6-reflected-cross-site-scripting-xss?_s_id=cve)