Quick Event Manager <= 9.6.4 - Authenticated(Admin+) Stored Cross-Site Scripting
Strategic Overview
- Status
- Patched in 9.6.5
- Affected Plugin
- Quick Event Manager
- Affected Version
<= 9.6.4- CVSS
- 5.5Medium
- Weakness type
- CWE-692 · Incomplete Denylist to Cross-Site Scripting
- CVE
CVE-2022-46863
At a glance
CVE-2022-46863 is a medium-severity Incomplete Denylist to Cross-Site Scripting vulnerability in the Quick Event Manager WordPress plugin, affecting versions <= 9.6.4. It carries a CVSS score of 5.5 (reachable over the network; low attack complexity). Exploitation requires an authenticated account at Admin level or above. The issue is fixed in version 9.6.5; sites on affected versions should update now. Disclosed February 2023, reported by Justiice.
Vulnerability Overview
The Quick Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.6.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user.
CWE-692: Incomplete Denylist to Cross-Site Scripting
The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.
Remediation
Update to version 9.6.5, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: Quick Event Manager 9.6.5 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Related records
Other vulnerabilities in Quick Event Manager
- 7.2CVE-2026-84848: Quick Event Manager <= 9.17 Stored XSS
CVE-2026-84848 - 7.2CVE-2023-23979: Quick Event Manager <= 9.7.4 Stored XSS
CVE-2023-23979 - 6.3CVE-2023-23975: Quick Event Manager Missing Authorization Checks
CVE-2023-23975 - 6.3CVE-2023-23974: Quick Event Manager <= 9.7.4 CSRF
CVE-2023-23974 - 6.3CVE-2022-4974: Freemius SDK <= 2.4.2 Missing Authorization Checks
CVE-2022-4974 - 6.1CVE-2023-23491: Quick Event Manager <= 9.7.4 Reflected XSS
CVE-2023-23491 - 5.3CVE-2026-84847: Quick Event Manager <= 9.17 Missing Authorization
CVE-2026-84847
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C