Event Timeline – Vertical Timeline [rich-event-timeline] <= 1.1.6 (unfixed)
unknown
[en] The Event Timeline WordPress plugin through 1.1.5 does not sanitize and escape Timeline Text, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
- Affected:
- up to 1.1.6
- Fix:
- No patched version reported
- Disclosed:
- Aug 1, 2022
CVE-2022-1324 on NVD →
Event Timeline <= 1.1.6 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Event Timeline WordPress plugin through 1.1.6 does not sanitize and escape Timeline Text, which could allow high-privileged users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
- CVSS:
- 5.5
- Affected:
- up to 1.1.6
- Fix:
- No patched version reported
- Disclosed:
- Jul 11, 2022
CVE-2022-1324 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database