cleantalk
Vulnerabilities and Security Researches

Easy PayPal Events, 2049e15c3250cb375a2ccc9932eaa1a42a43f653

Application

Easy PayPal Events

Published on
May 25, 2022
Research Description
Easy PayPal Events &amp; Tickets [easy-paypal-events-tickets] < 1.1.7 Easy PayPal Events <= 1.1.6 - Reflected Cross-Site Scripting via Page The Easy PayPal Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Please note several additional security fixes were made in versions up to 1.1.7.
Affected versions
max 1.1.7.
Status
vulnerable