MEDIUM
netweblogic
CVE published 2026-09-05
CVE-2025-14945
The Events Manager plugin for WordPress has a Stored Cross-Site Scripting vulnerability via event attribute values in versions up to 7.3.3. This vulnerability allows authenticated attackers with Author-level access or unauthenticated attackers when anonymous submissions are enabled to inject web scripts that execute when users view affected event pages. The vulnerability is due to insufficient input sanit [truncated]