CVE-2023-23491
Quick Event Manager < 9.7.5 - Cross-Site Scripting
Record summary
CVE-2023-23491 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Quick Event Manager WordPress Plugin | CVE List | < 9.7.5 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMQuick Event Manager < 9.7.5 - Cross-Site ScriptingCVSS 6.1
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.
Impact
Unauthenticated attackers can inject malicious JavaScript through the category parameter in the qem_ajax_calendar action to steal WordPress user session cookies and execute attacks.
Remediation
Fixed in version 9.7.5 and above
Source: ProjectDiscovery