CVE-2018-9020: Pixelite Events Manager
Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.
The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.
Affected products
- Pixelite Events Manager: before 5.8.1.2 (fixed in 5.8.1.2)
Published 2018-03-26. Last modified 2026-06-17.