The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against logged-in users.
Metrics
Affected Vendors & Products
References
History
Wed, 27 May 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against logged-in users. | |
| Title | EventPress < 22.2 – Reflected Cross-Site Scripting | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-05-27T06:00:03.944Z
Reserved: 2026-04-14T08:46:08.770Z
Link: CVE-2026-6268
No data.
Status : Received
Published: 2026-05-27T07:16:12.113
Modified: 2026-05-27T07:16:12.113
Link: CVE-2026-6268
No data.
OpenCVE Enrichment
No data.