CVE-2026-81791: WordPress EventON plugin <= 2.5.7 - Cross Site Scripting (XSS) vulnerability
Published Sep 10, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.
Affected Software
1 affected component
WordPress/EventON<=2.5.7
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attack requires subscriber-level privileges. It is network-accessible, has low attack complexity, and requires user interaction.
2
What is the potential impact if the vulnerability is exploited?
The CVSS vector indicates low impact to confidentiality, integrity, and availability, with a scope change (S:C). The reported severity is medium, with a 6.5 CVSS score.