Mobile Events Manager <= 1.4.7 - Authenticated (Administrator+) CSV Injection
low
The Mobile Events Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.7. This allows administrator level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulner...
- CVSS:
- 2.7
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.8
- Disclosed:
- Aug 17, 2022
CVE-2022-1194 on NVD →
Mobile Events Manager < 1.4.4 - Cross-Site Scripting
medium
The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Dec 24, 2021
CVE-2021-25049 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database