Junglewise Threat Intelligence

CVE-2026-42686: EventPrime Cross Site Scripting in WordPress plugin

CVE-2026-42686 · Severity: high · CVSS 7.1 · Published 2026-06-15

Technologies: EventPrime. Vendors: EventPrime.

Executive brief

EventPrime is a WordPress plugin used for managing event calendars and bookings. A security flaw allows users with basic 'Subscriber' accounts to inject malicious scripts into the website. This could lead to unauthorized redirects, the display of fraudulent advertisements, or the disruption of site operations for other visitors.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the EventPrime plugin for WordPress (versions 4.3.2.1 and below) due to improper neutralization of input during web page generation (CWE-79). The vulnerability requires Subscriber-level authentication to exploit. An attacker can inject malicious HTML or JavaScript payloads that execute in the context of other users' browsers. While the CVSS vector indicates a high impact on availability, the primary risk involves the injection of redirects or unauthorized content. The issue is resolved in version 4.3.2.2.

Affected products

  • EventPrime EventPrime <= 4.3.2.1

Timeline

  • 2026-04-24: other: Reported by researcher hhhai
  • 2026-05-24: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published to NVD
  • 2026-05-24: patched: Version 4.3.2.2 released to address the vulnerability

References

Related threats