CVE-2024-3492

Events Manager – Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 13,241 live websites that are affected by CVE-2024-3492.

Test my site




Affected Software

Product  Events Manager for WordPress
Category Wordpress Plugins
Vulnerable Domains13,241 live websites (34.48% of Events Manager for WordPress install base)
Vulnerable Versions
  • from 0 through 6.4.7.3
Vulnerable Versions Count85 versions ( 73.28% of all versions)



Details

  • Published - Jun 12, 2024
  • Updated - Aug 1, 2024

Credits

  • Matthew Rollings (finder)

CVE-2024-3492 usage by Country

United States3,801 websites



Germany2,542 websites
France1,214 websites
GB542 websites
Netherlands520 websites
Italy422 websites
Japan411 websites
Switzerland338 websites
Spain299 websites
Canada207 websites

CVE-2024-3492 usage by TLD

.com3,745 websites
.de1,653 websites
.org1,618 websites
.fr558 websites
.nl492 websites
.it355 websites
.co.uk297 websites
.ch276 websites
.net274 websites
.at232 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-3492

Top websites that are affected by CVE-2024-3492. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.*******.**********.it Italy**,***
*********.*******.org United States**,***
******.***.uk United States**,***
*******.org United States**,***
********.org United States**,***
*****.***.edu United States**,***
****.**.in United States**,***
********************.com United States**,***
*************.cat Spain***,***
**************.it Italy***,***
See full domain list

FAQ

A total of 13,241 websites have been identified as vulnerable to CVE-2024-3492, discovered through global website indexing conducted by WebTechSurvey.
Events Manager for WordPress is susceptible to CVE-2024-3492 vulnerability.
Events Manager for WordPress versions before, and including, 6.4.7.3 are vulnerable to CVE-2024-3492.