Input validation vulnerability in EventPress 1.0.0

The plugin called EventPress, which is used with WordPress, has a security issue. This issue, known as Stored Cross-Site Scripting, affects versions 1.0.0 and below. The problem is that the plugin does not properly clean or protect the input and output of data. This means that attackers who have contributor-level access or higher can insert their own harmful web scripts into pages. When a user visits these pages, the scripts will run without their knowledge.

Detected in:

EventPress fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.