vulnerability with plugin?? message from SiteLock
-
I got this message today: “Your complimentary SiteLock scanner has found a vulnerability on your website.” SiteLock is connected to MyDomain.com, which hosts my site. The scan found a vulnerability related to the events manager plugin. I didn’t find any plugin updates, so I was told to check with the developer of the plugin for any additional patches or information back from them on the plugin. MyDomain/SiteLock support guy said:
“This is the information that I can provide you….
Events Manager 5.9.5
Severity: Critical
Category: xss
Summary: Events Manager < 5.9.5 – Multiple XSS
Description: WordPress plugin Events Manager version 5.9.5 and prior suffers from multiple XSS vulnerabilities. There is multiple stored XSS(Cross-site Scripting) in file events-manager/trunk/admin/settings/tabs/pages.php events-manager-options page. The reason – Unsanitized user’s input from the following parameters: dbem_cp_events_slug dbem_cp_locations_slug dbem_taxonomy_category_slug dbem_taxonomy_tag_slug Exploiting this vulnerability requires authentication. Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites. XSS attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user within the output it generates without validating or encoding it.”Anyone know what to do? THANKS!
The page I need help with: [log in to see the link]
- The topic ‘vulnerability with plugin?? message from SiteLock’ is closed to new replies.