vendor:
Eventon Calendar
by:
b3kc4t (Mustafa GUNDOGDU)
7.5
CVSS
HIGH
Reflected Cross-Site Scripting
79
CWE
Product Name: Eventon Calendar
Affected Version From: 3.0.5
Affected Version To: 3.0.5
Patch Exists: YES
Related CWE: 2020-29395
CPE: a:myeventon:eventon_calendar:3.0.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04
2020
WordPress Plugin EventON Calendar 3.0.5 – Reflected Cross-Site Scripting
WordPress sites that use EventOn Calendar cause reflected xss vulnerability to javascript payloads injected into the search field.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.