CVE-2018-9020: Pixelite Events Manager

Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.

The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.

Affected products

  • Pixelite Events Manager: before 5.8.1.2 (fixed in 5.8.1.2)

Published 2018-03-26. Last modified 2026-06-17.