WordPress 插件 “The Events Manager – Calendar, Bookings, Tickets, and more!” 存在反射型跨站脚本漏洞(Reflected Cross-Site Scripting)。该漏洞存在于所有 7.4.0.1 及以下版本中,原因是插件对 ‘header_format’ 参数缺乏充分的输入清理和输出转义。 攻击者无需身份验证,即可通过诱使用户执行特定操作(例如点击恶意链接),在受影响页面中注入任意 Web 脚本。 虽然插件通过 shortcode 入口使用
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| netweblogic | Events Manager – Calendar, Bookings, Tickets, and more! | ≤ 7.4.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| netweblogic | Events Manager – Calendar, Bookings, Tickets, and more! | 0 ~ 7.4.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14280 | 6.6 MEDIUM | Events Manager <= 7.3.7.4 - Authenticated (Administrator+) Local File Inclusion via 'dbem_ |
| CVE-2026-15023 | 6.5 MEDIUM | Events Manager <= 7.4.0 - Authenticated (Contributor+) SQL Injection via 'meta_key' Parame |
| CVE-2026-10627 | 5.3 MEDIUM | Events Manager <= 7.4.0 - Missing Authorization to Unauthenticated Sensitive Information D |
No comments yet