CVE-2023-23491: Fullworksplugins Quick Event Manager

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

The Quick Event Manager WordPress Plugin, version < 9.7.5, is affected by a reflected cross-site scripting vulnerability in the 'category' parameter of its 'qem_ajax_calendar' action.

Affected products

Published 2023-01-20. Last modified 2026-06-17.