Impact
The vulnerability is a reflected XSS flaw caused by Tehsmash Ultimate Events failing to neutralize user‑supplied data before displaying it. Injected JavaScript is returned to the victim’s browser and can run in the context of the page, but the description does not specify any additional impacts beyond this client‑side execution.
Affected Systems
The flaw is present in all releases of the Ultimate Events plugin up to and including version 1.3.3, and therefore any WordPress site that has installed or upgraded to those versions without applying a later fix is vulnerable. No additional platform or configuration requirements are mentioned, so the impact applies to all audiences that use this plugin.
Risk and Exploitability
The CVSS score of 7.1 signals a high severity, but the EPSS score of less than 1% suggests that real‑world exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need an end‑user to click a crafted link or interact with a form that contains malicious script; the reflected nature of the flaw makes exploitation dependent on user interaction but allows JavaScript execution within the victim’s browser.
OpenCVE Enrichment
EUVD