The EventON-RSVP WordPress plugin before 2.9.5 does not...
Moderate severity
Unreviewed
Published
Jan 22, 2024
to the GitHub Advisory Database
•
Updated May 30, 2025
Description
Published by the National Vulnerability Database
Jan 22, 2024
Published to the GitHub Advisory Database
Jan 22, 2024
Last updated
May 30, 2025
The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
References