Input validation vulnerability in Event post 5.8.6

The Event post plugin for WordPress has a security vulnerability that allows attackers with certain permissions to inject dangerous web scripts into pages. This means that when a user accesses an affected page, the malicious scripts will be executed. This vulnerability affects all versions of the plugin up to version 5.8.6 and is caused by inadequate input sanitization and output escaping of user-supplied attributes.

Detected in:

Event post open vulnerable versions: >= * <= 5.9.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.