# Exploit Title: WordPress Plugin WP Event Manager - Stored Cross Site Scripting # Date: 15-05-2022 # Exploit Author: Mariam Tariq - HunterSherlock # Vendor Homepage: https://wordpress.org/plugins/wp-event-manager/ # Version: 3.1.27 # Tested on: Firefox # Contact me: mariamtariq404@gmail.com #Steps To Reproduce : 1 - First Install the plugins - wp-event-manager and activate it. 2 - Go to event manager â> Add New 3 - Inside the ââEvent Titleâ at the top, enter XSS payload â><img src=x onerror=alert(1)> and hit publish. 4 - Check the newly made eventâs URL /event/{id}/ , XSS will trigger. #Poc Image : https://imgur.com/J1Q3x5u