Event List < 0.8.7 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Event List WordPress plugin through 0.8.8 does not sanitise and escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks against other admin even when the unfiltered_html is disallowed
- CVSS:
- 5.5
- Affected:
- up to 0.8.7
- Fixed in:
- 0.8.8
- Disclosed:
- Apr 18, 2022
CVE-2022-0418 on NVD →
Event List <= 0.7.9 - Unauthenticated Cross-Site Scripting
medium
The Event List plugin 0.7.9 for WordPress has XSS in the slug array parameter to wp-admin/admin.php in an el_admin_categories delete_bulk action.
- CVSS:
- 6.1
- Affected:
- up to 0.7.9
- Fixed in:
- 0.7.10
- Disclosed:
- Jul 31, 2017
CVE-2017-12068 on NVD →
Event List < 0.7.9 - Authenticated (Admin+) SQL Injection
high
The Event List plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in versions before 0.7.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append additional...
- CVSS:
- 7.2
- Affected:
- up to 0.7.9
- Fixed in:
- 0.7.9
- Disclosed:
- Jun 4, 2017
CVE-2017-9429 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database