← العودة للجدول
CVE-2026-7421
CVE-2026-7421 — GHSA: The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all...
📅 2026-06-03
🟡 Medium 🔥 No GHSA Exploit Web CVSS 4.4

📋 الوصف الكامل

The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name` setting value without sanitization when it begins with "http", combined with insufficient validation in the `validate_shop_name()` function which only checks for empty values and string type

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-7421

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←