Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikAppointments Services Booking Calendar vikappointments allows Stored XSS.This issue affects VikAppointments Services Booking Calendar: from n/a through <= 1.2.16.
Published: 2025-01-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

VikAppointments Services Booking Calendar is vulnerable to improper input neutralization that allows malicious code to be stored and executed within the browser context of any user who accesses the affected booking interface. The flaw is a classic stored cross‑site scripting issue (CWE‑79) that can be used to hijack user sessions, deface content, or exfiltrate data. The affected plugin versions have a base score of 7.1, indicating moderate severity with potential high impact if exploited.

Affected Systems

The vulnerability exists in the VikAppointments Services Booking Calendar WordPress plugin for all releases up to and including 1.2.16. Any WordPress installation that has installed this plugin within that version range is potentially affected. The vendor, e4jvikwp, does not list a product beyond 1.2.16 as affected, so newer plugin releases are presumed secure.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalogue, so the likelihood of a known exploit is currently low. However, the CVSS score of 7.1 combined with the stored XSS nature means an attacker who can submit malicious input through the booking form can inject code that remains persistent for all future visitors. Since the flaw requires an input vector that is represented on the web interface, the attack path is typically through an authenticated or publicly accessible booking form where the input is not properly encoded before storage.

Generated by OpenCVE AI on May 1, 2026 at 19:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the VikAppointments plugin to version 1.2.17 or later, which contains the XSS fix.
  • If updating immediately is impossible, disable or remove any custom fields that allow free‑form input until the patch is applied, and ensure all remaining form inputs are properly escaped when rendered.
  • Deploy a web application firewall or clientside XSS filtering to detect and block injected scripts, and monitor site logs for XSS attempts.

Generated by OpenCVE AI on May 1, 2026 at 19:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2940 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E4J s.r.l. VikAppointments Services Booking Calendar allows Stored XSS. This issue affects VikAppointments Services Booking Calendar: from n/a through 1.2.16.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E4J s.r.l. VikAppointments Services Booking Calendar allows Stored XSS. This issue affects VikAppointments Services Booking Calendar: from n/a through 1.2.16. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikAppointments Services Booking Calendar vikappointments allows Stored XSS.This issue affects VikAppointments Services Booking Calendar: from n/a through <= 1.2.16.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jan 2025 14:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E4J s.r.l. VikAppointments Services Booking Calendar allows Stored XSS. This issue affects VikAppointments Services Booking Calendar: from n/a through 1.2.16.
Title WordPress VikAppointments Services Booking Calendar plugin <= 1.2.16 - CSRF to Stored XSS vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:05.928Z

Reserved: 2025-01-07T21:03:44.259Z

Link: CVE-2025-22719

cve-icon Vulnrichment

Updated: 2025-02-12T20:28:10.954Z

cve-icon NVD

Status : Deferred

Published: 2025-01-21T14:15:11.860

Modified: 2026-06-17T08:49:31.887

Link: CVE-2025-22719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T20:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')