Executive brief
Quick Event Manager is a WordPress plugin for managing events. An unauthenticated attacker can inject malicious scripts into the plugin that execute in the browsers of site visitors, potentially stealing login credentials, session tokens, or sensitive personal data from attendees and administrators.
Technical details
This is an unauthenticated Cross Site Scripting (XSS) vulnerability in the Quick Event Manager WordPress plugin affecting versions 9.17 and earlier (some sources indicate 9.18). The vulnerability allows an attacker to inject malicious JavaScript into the application without requiring authentication. The attack vector is network-based and does not require direct user interaction beyond a visitor accessing an affected page or component. Successful exploitation enables the attacker to steal session cookies, session tokens, credentials, or execute actions on behalf of victims. No official patch has been released as of the advisory publication date (September 3, 2026); mitigation via Web Application Firewall rules is available.
Affected products
- Bright Plugins Quick Event Manager <= 9.18
Timeline
- 2026-05-31: disclosed: Reported to Patchstack by ParkHyunWoo
- 2026-09-03: advisory: Published on NVD and Patchstack