Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation, known as Cross‑Site Scripting, in the WP Event Aggregator plugin by Xylus Themes. A malicious actor can craft input that is reflected in a generated web page, allowing the execution of arbitrary client‑side scripts when a user visits a specially formatted URL. This can lead to session hijacking, defacement, or redirection to phishing sites, compromising the confidentiality and integrity of user sessions.
Affected Systems
The flaw affects installations of the WP Event Aggregator plug‑in for WordPress from unspecified previous releases through version 1.8.2, as supplied by Xylus Themes. The vulnerable code resides in the plugin’s web page generation logic and is present in any site that has not yet upgraded beyond 1.8.2.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity with medium exploitability. The EPSS score of less than 1% suggests that exploitation is currently rare or unlikely, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a crafted request to the plugin’s front‑end that includes non‑sanitized parameters, producing a reflected XSS payload that is executed in the victim’s browser.
OpenCVE Enrichment
EUVD