Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 27 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eventespresso
Eventespresso event Espresso Wordpress Wordpress wordpress |
|
| Vendors & Products |
Eventespresso
Eventespresso event Espresso Wordpress Wordpress wordpress |
Wed, 27 May 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Wed, 27 May 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against logged-in users. | |
| Title | EventPress < 22.2 – Reflected Cross-Site Scripting | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-05-27T13:02:25.088Z
Reserved: 2026-04-14T08:46:08.770Z
Link: CVE-2026-6268
Updated: 2026-05-27T13:02:16.371Z
Status : Deferred
Published: 2026-05-27T07:16:12.113
Modified: 2026-05-27T14:55:09.597
Link: CVE-2026-6268
No data.
OpenCVE Enrichment
Updated: 2026-05-27T16:00:08Z