Record summary

CVE-2023-23491 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Quick Event Manager WordPress Plugin

CVE List< 9.7.5affected

Nuclei templates

1
ProjectDiscoveryMEDIUMQuick Event Manager < 9.7.5 - Cross-Site ScriptingCVSS 6.1

The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.

Impact

Unauthenticated attackers can inject malicious JavaScript through the category parameter in the qem_ajax_calendar action to steal WordPress user session cookies and execute attacks.

Remediation

Fixed in version 9.7.5 and above

WeaknessesCWE-79
Authorsritikchaddha
Template tagscve2023cvewordpresswpwp-pluginwpscanxssquick-event-managerfullworkspluginsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:fullworksplugins:quick_event_manager:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/quick-event-manager
FOFA: body=/wp-content/plugins/quick-event-manager

Source: ProjectDiscovery

References

2