CVE-2026-6268 PUBLISHED

EventPress < 22.2 – Reflected Cross-Site Scripting

Assigner: WPScan
Reserved: 14.04.2026 Published: 27.05.2026 Updated: 27.05.2026

The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_notify_dismiss_action AJAX handler before outputting it back in the response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against logged-in users.

Product Status

Vendor Unknown
Product EventPress
Versions Default: unaffected
  • affected from 0 to 22.2 (excl.)

Credits

  • Mustafa Ahmed finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE