The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.
id: CVE-2023-23491
info:
name: Quick Event Manager < 9.7.5 - Cross-Site Scripting
author: ritik
...