Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form booking-calendar-contact-form allows Stored XSS.This issue affects Booking Calendar Contact Form: from n/a through <= 1.2.55.
Published: 2025-01-24
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw rooted in improper neutralization of user input during page generation within the Booking Calendar Contact Form plugin. Attackers can inject malicious script code into form fields that are later rendered unescaped to other site visitors. If an attacker succeeds, the script executes within the victim’s browser with the same privileges as the user, enabling payload execution such as session hijacking, cookie theft, or defacement. The weakness falls under CWE‑79 and compromises the confidentiality and integrity of the affected website.

Affected Systems

This issue affects WordPress sites running the codepeople Booking Calendar Contact Form plugin, version 1.2.55 and earlier. The plugin is available through the WordPress plugin repository and is commonly used for booking and contact form functionalities. No granular sub‑version information is supplied beyond the <=1.2.55 ceiling.

Risk and Exploitability

The published CVSS score of 5.9 indicates a moderate severity for this stored XSS. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker to craft a payload via the plugin’s form interface; the payload is stored until displayed to other authenticated or unauthenticated users. Attackers could abuse this path to steal credentials or inject malicious content once they control the data to be stored.

Generated by OpenCVE AI on May 1, 2026 at 18:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Booking Calendar Contact Form plugin to the latest version that includes the stored XSS fix.
  • If an upgrade is infeasible, restrict the plugin’s form access to a trusted administrator role and disable any features that allow arbitrary HTML input.
  • Apply general input sanitization on all user‑supplied data, ensuring that output encoding is performed before rendering on the site.

Generated by OpenCVE AI on May 1, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3915 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Booking Calendar Contact Form allows Stored XSS. This issue affects Booking Calendar Contact Form: from n/a through 1.2.55.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Booking Calendar Contact Form allows Stored XSS. This issue affects Booking Calendar Contact Form: from n/a through 1.2.55. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking Calendar Contact Form booking-calendar-contact-form allows Stored XSS.This issue affects Booking Calendar Contact Form: from n/a through <= 1.2.55.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 12 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Booking Calendar Contact Form allows Stored XSS. This issue affects Booking Calendar Contact Form: from n/a through 1.2.55.
Title WordPress Booking Calendar Contact Form Plugin <= 1.2.55 - Stored Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Codepeople Booking Calendar Contact Form
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:32.983Z

Reserved: 2025-01-23T14:52:44.767Z

Link: CVE-2025-24723

cve-icon Vulnrichment

Updated: 2025-02-12T19:55:02.477Z

cve-icon NVD

Status : Deferred

Published: 2025-01-24T18:15:46.000

Modified: 2026-04-23T15:25:22.207

Link: CVE-2025-24723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T18:30:05Z

Weaknesses