CVE Vulnerabilities

CVE-2023-1126

Published: Apr 24, 2023 | Modified: Feb 04, 2025
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The WP FEvents Book WordPress plugin through 0.46 does not sanitise and escape some parameters, which could allow any authenticated users, such as subscriber to perform Cross-Site Scripting attacks

Affected Software

NameVendorStart VersionEnd Version
Wp_fevents_bookWp_fevents_book_project*0.46 (including)

References