First published: Tue Jun 20 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Metagauss Eventprime | <=3.0.5 |
Update to 3.0.6 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35884 is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the EventPrime plugin version 3.0.5 and earlier.
The severity of CVE-2023-35884 is high, with a CVSS score of 6.1.
CVE-2023-35884 affects the EventPrime plugin version 3.0.5 and earlier, allowing unauthenticated attackers to inject and execute malicious scripts in the victim's browser.
To fix CVE-2023-35884, upgrade to a version of the EventPrime plugin that is later than 3.0.5, as this vulnerability has been patched in the newer versions.
For more information about CVE-2023-35884 and its impact, you can refer to the official reference: [CVE-2023-35884 Reference](https://patchstack.com/database/vulnerability/eventprime-event-calendar-management/wordpress-eventprime-plugin-3-0-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve)