CVE-2026-84848: WordPress Quick Event Manager plugin <= 9.17 - Cross Site Scripting (XSS) vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
Affected Software
1 affected component
wordpress/quick-event-manager<=9.17
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Quick Event Manager pluginto a version that resolves this vulnerability.Fixed in 9.17
Event History
Sep 3, 2026
CVE Published
via MITRE·04:32 PM
Data Sourced
via MITRE·04:32 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or plugin-specific privileges. Exploitation still requires user interaction, as indicated by the UI:R attack vector.
2
Which plugin versions are affected?
Quick Event Manager versions 9.17 and earlier are affected.
3
What is the potential impact if exploitation succeeds?
Successful XSS exploitation can affect confidentiality, integrity, and availability at a low level. The scope is changed, meaning the impact may extend beyond the vulnerable plugin's security authority.