CVE-2023-23491: Fullworksplugins Quick Event Manager
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.
Affected products
- Fullworksplugins Quick Event Manager: before 9.7.5 (fixed in 9.7.5)
Published 2023-01-20. Last modified 2026-06-17.