The Events Manager WordPress plugin prior to 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
wp-events-plugin events manager |