plugin

Mobile Events Manager Vulnerabilities

2 known security issues reported for the Mobile Events Manager WordPress plugin. Most recent disclosed Aug 17, 2022.

1 medium 1 low

Running Mobile Events Manager on your site? Check whether your installed version is affected.

Scan your site free

Mobile Events Manager <= 1.4.7 - Authenticated (Administrator+) CSV Injection

low

The Mobile Events Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.7. This allows administrator level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulner...

CVSS:
2.7
Affected:
up to 1.4.7
Fixed in:
1.4.8
Disclosed:
Aug 17, 2022

CVE-2022-1194 on NVD →

Mobile Events Manager < 1.4.4 - Cross-Site Scripting

medium

The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
5.5
Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Dec 24, 2021

CVE-2021-25049 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database