CVE-2023-47697: WordPress WP Event Manager Plugin <= 3.1.39 is vulnerable to Cross Site Scripting (XSS)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin <= 3.1.39 versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-47697?
CVE-2023-47697 is a vulnerability in the WordPress WP Event Manager Plugin versions up to 3.1.39 that allows for cross-site scripting (XSS) attacks.
How severe is CVE-2023-47697?
CVE-2023-47697 has a severity rating of 7.1 (high).
How does CVE-2023-47697 affect the WP Event Manager plugin?
CVE-2023-47697 affects WP Event Manager plugin versions up to 3.1.39, allowing for unauthenticated reflected cross-site scripting (XSS) attacks.
How can I fix CVE-2023-47697?
To fix CVE-2023-47697, update the WP Event Manager plugin to version 3.1.40 or later.
Can I find more information about CVE-2023-47697?
Yes, you can find more information about CVE-2023-47697 at the following reference link: [Reference Link](https://patchstack.com/database/vulnerability/wp-event-manager/wordpress-wp-event-manager-plugin-3-1-39-cross-site-scripting-xss-vulnerability?_s_id=cve)