CVE-2023-5238 Information

Description

The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page leading to an HTML Injection on the plugin in the search area of the website.

Reference

https://wpscan.com/vulnerability/47a5fbfd-f47c-4356-8567-b29dadb48423

Share on: