Back

MEDIUM

MotoPress Timetable and Event Schedule Quick Edit admin-ajax.php cross site scripting

Published Aug 16, 2022

Description

A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /wp-admin/admin-ajax.php of the component Quick Edit. The manipulation of the argument post_title with the input <img src=x onerror=alert`2`> leads to cross site scripting. The attack may be launched remotely. VDB-206486 is the identifier assigned to this vulnerability.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulDB
Published Aug 16, 2022
Updated Apr 15, 2025
Reserved Aug 16, 2022

CISA Vulnrichment

Updated Apr 14, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner VulDB
Published Aug 16, 2022
Updated Apr 15, 2025

GitHub

No data