Impact
The Weekly Planner plugin for WordPress suffers a stored cross‑site scripting vulnerability due to insufficient input sanitization and output escaping in admin settings. Attackers with administrator privileges can inject arbitrary JavaScript that will run whenever a user opens an injected page, potentially enabling session hijacking, defacement, or other client‑side attacks.
Affected Systems
All WordPress installations using Weekly Planner version 1.0 or earlier, especially multisite deployments with unfiltered_html disabled. The vulnerability applies to the Michael J. Reid Weekly Planner plugin and must be addressed on any affected site.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity, and an EPSS of less than 1% suggests a very low but non‑zero probability of exploitation. The plugin is not listed in CISA KEV. Exploitation requires administrator rights on a multisite configuration, making it a targeted attack vector rather than a widespread threat.
OpenCVE Enrichment