CVE-2023-35884: WordPress EventPrime Plugin <= 3.0.5 is vulnerable to Cross Site Scripting (XSS)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress EventPrime Pluginto a version that resolves this vulnerability.Fixed in 3.0.6
Event History
Frequently Asked Questions
What is CVE-2023-35884?
CVE-2023-35884 is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the EventPrime plugin version 3.0.5 and earlier.
What is the severity of CVE-2023-35884?
The severity of CVE-2023-35884 is high, with a CVSS score of 6.1.
How does CVE-2023-35884 affect the EventPrime plugin?
CVE-2023-35884 affects the EventPrime plugin version 3.0.5 and earlier, allowing unauthenticated attackers to inject and execute malicious scripts in the victim's browser.
How can I fix CVE-2023-35884?
To fix CVE-2023-35884, upgrade to a version of the EventPrime plugin that is later than 3.0.5, as this vulnerability has been patched in the newer versions.
Is there any additional information about CVE-2023-35884?
For more information about CVE-2023-35884 and its impact, you can refer to the official reference: [CVE-2023-35884 Reference](https://patchstack.com/database/vulnerability/eventprime-event-calendar-management/wordpress-eventprime-plugin-3-0-5-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve)