CVE-2023-6046Cross-site Scripting in Eventon

Severity
4.8MEDIUMNVD
EPSS
0.1%
top 76.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 16

Description

The EventON WordPress plugin before 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored HTML Injection attacks even when the unfiltered_html capability is disallowed.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-m6vj-6wj8-cpxm: The EventON WordPress plugin before 22024-01-16
CVEList
EventON < 2.2 - Admin+ Stored HTML Injection2024-01-16
CVE-2023-6046 — Cross-site Scripting in Eventon | cvebase