Impact
The vulnerability is an improper neutralization of input that allows a stored cross‑site scripting flaw in the Huurkalender WP plugin. An attacker can inject malicious JavaScript that is permanently saved and later rendered by the plugin, causing the script to execute in the browsers of any site visitor. Such code execution can steal authentication cookies, track user activity, hijack sessions, or perform other malicious actions, thereby compromising the confidentiality and integrity of the site’s data.
Affected Systems
Affects the Huurkalender.nl WordPress Huurkalender WP plugin on any WordPress installation that is running version 1.5.6 or older. Versions newer than 1.5.6 are not impacted according to the advisory provided.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present. The vulnerability is not listed in CISA KEV, so no known large‑scale exploitation campaigns are reported. The risk arises when a user with the ability to input data into the plugin (for example, a contributor or administrator) inserts malicious code. The plugin then stores and later outputs the unsanitized input, enabling the XSS to trigger against any visitor who views the affected content.
OpenCVE Enrichment
EUVD