The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 13,241 live websites that are affected by CVE-2024-3492.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 13,241 live websites (34.48% of Events Manager for WordPress install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 85 versions ( 73.28% of all versions) |
![]() | 3,801 websites |
![]() | 2,542 websites |
![]() | 1,214 websites |
![]() | 542 websites |
![]() | 520 websites |
![]() | 422 websites |
![]() | 411 websites |
![]() | 338 websites |
![]() | 299 websites |
![]() | 207 websites |
.com | 3,745 websites |
.de | 1,653 websites |
.org | 1,618 websites |
.fr | 558 websites |
.nl | 492 websites |
.it | 355 websites |
.co.uk | 297 websites |
.ch | 276 websites |
.net | 274 websites |
.at | 232 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
****.*******.**********.it | ![]() | **,*** | |
*********.*******.org | ![]() | **,*** | |
******.***.uk | ![]() | **,*** | |
*******.org | ![]() | **,*** | |
********.org | ![]() | **,*** | |
*****.***.edu | ![]() | **,*** | |
****.**.in | ![]() | **,*** | |
********************.com | ![]() | **,*** | |
*************.cat | ![]() | ***,*** | |
**************.it | ![]() | ***,*** |
FAQ