Impact
The sebkay Calendi WordPress plugin contains a flaw where user input is reflected in the webpage without proper escaping, creating a reflected Cross‑Site Scripting (XSS) vulnerability. This allows an attacker to inject arbitrary JavaScript that will execute in the context of a victim’s browser when the page is rendered, potentially exposing or manipulating the content displayed to that user.
Affected Systems
The vulnerability affects the Calendi plugin for WordPress provided by sebkay. Any installation running any build from the earliest available versions up through 1.1.1 inclusive is vulnerable; no later releases are known to contain the fix.
Risk and Exploitability
The CVSS score of 7.1 conveys a high severity level. The EPSS score of less than 1% indicates that exploitation is currently considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. The attack likely requires an attacker to persuade a victim to open a crafted URL or submit malicious input that the plugin reflects back, a scenario inferred from the nature of reflected XSS.
OpenCVE Enrichment
EUVD