mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-07 17:36:58 +02:00
675 B
675 B
CVE-2018-9020
Description
The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.
POC
Reference
- https://www.gubello.me/blog/events-manager-authenticated-stored-xss/
- https://www.youtube.com/watch?v=40d7uXl36O4
Github
No PoCs found on GitHub currently.