Required CVE Record Information
Description
The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- https://wordpress.org/plugins/events-manager/#developers x_transferred
- https://www.gubello.me/blog/events-manager-authenticated-stored-xss/ x_transferred
- https://www.youtube.com/watch?v=40d7uXl36O4 x_transferred
- http://wp-events-plugin.com/blog/2018/01/15/events-manager-5-8-1-2-security-release/ x_transferred