Impact
The vulnerability is a stored cross‑site scripting flaw caused by inadequate input sanitization. An attacker could inject malicious script that is rendered when end‑users view a page managed by UniTimetable, potentially hijacking user sessions, defacing content, or loading third‑party resources. The flaw is a classic input validation weakness matched to CWE‑79.
Affected Systems
Affected systems include WordPress sites running the UniTimetable plugin version 1.1 or earlier, distributed by the author antrouss. The patch available in version 1.2 or later addresses the issue; sites presently using any version from the initial release through 1.1 are vulnerable.
Risk and Exploitability
The published CVSS score of 6.5 indicates moderate severity; the EPSS score of less than 1% suggests low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed widespread active exploitation. Attackers would likely target sites via the plugin’s data entry interface, so privileged or authenticated users who can add or edit events could act as vectors. Given the absence of remote code execution, the threat focus remains on session hijacking and defacement.
OpenCVE Enrichment
EUVD