Junglewise Threat Intelligence

CVE-2026-81791: EventON Cross Site Scripting (XSS) in subscriber input

CVE-2026-81791 · Severity: medium · CVSS 6.5 · Published 2026-09-10

Executive brief

EventON is a popular WordPress plugin for creating and managing events on websites. A Cross Site Scripting (XSS) vulnerability in versions 2.5.7 and earlier allows subscribers to inject malicious scripts into the site, which could steal visitor data or compromise user accounts when other users interact with the affected content.

Technical details

The vulnerability is a Stored/Reflected Cross Site Scripting (XSS) flaw in the EventON WordPress plugin affecting versions 2.5.7 and below. The vulnerability requires subscriber-level privileges and user interaction (such as clicking a malicious link or visiting a crafted page) to be exploited. Successful exploitation enables attackers to inject and execute arbitrary JavaScript code in the context of the website, potentially allowing data theft, session hijacking, or account compromise. The vulnerability has been patched in version 2.5.8 and later.

Affected products

  • EventON EventON <=2.5.7

Timeline

  • 2026-09-08: disclosed: Vulnerability disclosed by Patchstack
  • 2026-09-08: patched: Patched in version 2.5.8

References