Event Espresso Core <= 4.10.6.p - Reflected Cross-Site Scripting
mediumA cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php in the Event Espresso Core plugin before 4.10.7.p for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.
- CVSS:
- 6.1
- Affected:
- up to 4.10.6.p
- Fixed in:
- 4.10.7.p
- Disclosed:
- Jun 25, 2021