CVE-2020-35037: Pixelite Events Manager

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues

Affected products

  • Pixelite Events Manager: before 5.9.8 (fixed in 5.9.8)

Published 2021-12-01. Last modified 2026-06-17.