CVE-2024-5889: Events Manager <= 6.4.8 - Reflected Cross-Site Scripting
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Events Manager pluginto a version that resolves this vulnerability.Fixed in 6.4.8 - Configuration
Update the Events Manager plugin so the 'country' parameter is properly input-sanitized and output-escaped to prevent reflected XSS in all pages using that parameter.
WordPress Events Manager plugin country parameter input sanitization/output escaping = sanitized and escaped (fix reflected XSS)
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5889?
CVE-2024-5889 has a medium severity rating due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2024-5889?
To fix CVE-2024-5889, update the Events Manager plugin for WordPress to version 6.4.9 or later.
What software is affected by CVE-2024-5889?
CVE-2024-5889 affects all versions of the Events Manager plugin for WordPress up to and including version 6.4.8.
What exploits are associated with CVE-2024-5889?
CVE-2024-5889 allows attackers to execute scripts in the context of the user, potentially leading to data theft and session hijacking.
What is the impact of CVE-2024-5889 on my website?
If exploited, CVE-2024-5889 could allow attackers to inject malicious scripts, compromising user data and site integrity.