Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of input during web page generation. The flaw exists in the FAT Event Lite WordPress plugin for all versions up to and including 1.1. An attacker who can insert malicious script into a content field that the plugin stores and later displays can cause that script to run in the browsers of any visitor who views the affected content, potentially allowing arbitrary code execution in the victim’s browser.
Affected Systems
This issue impacts sites that have installed the FAT Event Lite plugin from roninwp. Versions 1.1 and earlier are affected. Any WordPress site running these versions contains the flaw until the plugin is upgraded to a patched release.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of less than 1% suggests a low likelihood of public exploitation at this time, and the vulnerability is not listed in the CISA KEV catalogue. Based on the type of flaw, the likely attack vector is web-based, requiring an attacker to inject script into a stored content field. While exploitation is possible, the current exploitation probability is low.
OpenCVE Enrichment
EUVD