Events Made Easy WordPress plugin CSRF + Persistent XSS

Posted by David Sopas on Oct 17

Plugin link: https://wordpress.org/plugins/events-made-easy/
Active Installs: 10,000+
Version tested: 1.5.49
CVE Reference: Waiting
Original advisory:
https://www.davidsopas.com/events-made-easy-wordpress-plugin-csrf-persistent-xss/

Events Made Easy is a full-featured event management solution for
WordPress. Events Made Easy supports public, private, draft and recurring
events, locations management, RSVP (+ optional approval), Paypal,
2Checkout,…

Leave a Reply