HomeDefault status
unaffected
Any version before 2.3.8
affected
Description
The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks
Problem types
CWE-79 Cross-Site Scripting (XSS)
Product status
Any version before 2.3.8
Credits
Anas Jamal and Satyam Singh
WPScan
References
wpscan.com/...rability/bf431b81-2db9-4fcb-841c-9b51d1870bf8/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.