Impact
The Community Events plugin for WordPress contains a stored cross‑site scripting flaw that allows an attacker to embed arbitrary scripts into the event details field. Because input sanitization and output escaping are insufficient, the malicious script runs in the browser context of any user who views the affected event page. This flaw can be used to steal session cookies, deface the site, or perform other client‑side attacks without requiring authentication.
Affected Systems
WordPress installations using the Community Events plugin from Jackdewey version 1.5.2 or earlier are affected. All releases up to and including 1.5.2 allow the flaw to be exercised.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability, but an EPSS score of less than 1% suggests that exploitation in the wild is currently rare. The flaw is not yet listed in the CISA KEV catalog. The attack vector is unauthenticated, relying on rogue input to the event details parameter, and any user who accesses the injected page will execute the injected code.
OpenCVE Enrichment