CVE-2023-0144
Event Manager and Tickets Selling Plugin for WooCommerce < 3.8.0 - Contributor+ Stored XSS
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
06 Feb 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Event Manager and Tickets Selling Plugin for WooCommerce WordPress plugin before 3.8.0 does not validate and escape some of its post meta before outputting them back in a page/post, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · Event Manager and Tickets Selling Plugin for WooCommerceWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →