Impact
The flaw is a reflected cross‑site scripting vulnerability in the Awesome Event Booking WordPress plugin, classified as CWE-79. It permits an attacker to inject arbitrary client‑side scripts into the HTML output that the site delivers. When a victim follows a carefully crafted URL or submits manipulated data that is not properly sanitized, the malicious script is echoed back to the browser, enabling potential cookie theft, session hijacking, page defacement, or redirection to phishing sites.
Affected Systems
All WordPress sites running the AwesomeTOGI Awesome Event Booking plugin up to and including version 2.7.1 are impacted. The vulnerability resides solely within the plugin code and does not affect core WordPress or other plugins.
Risk and Exploitability
The CVSS score of 7.1 reflects a high‑severity risk, yet the EPSS value of less than 1% indicates a very low current exploitation probability. The flaw is not listed in CISA’s KEV catalog. Exploitation requires active user interaction—visiting a malicious link or submitting crafted input—so the attack surface is limited to individuals who can access the vulnerable plugin’s reflected output paths.
OpenCVE Enrichment
EUVD