Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in accreteinfosolution Appointment Buddy Widget appointment-buddy-online-appointment-booking-by-accrete allows Cross-Site Scripting (XSS).This issue affects Appointment Buddy Widget: from n/a through <= 1.2.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper neutralization of input during web page generation that permits a reflected cross‑site scripting attack. When an attacker supplies crafted data to the Appointment Buddy Widget, the plugin fails to encode or validate the content before emitting it to the browser. An affected user who loads a page containing the bad input would receive and execute malicious JavaScript. This can compromise session cookies, steal authentication tokens, inject phishing pages, or deface the site in the context of the victim’s browser.

Affected Systems

The vulnerability exists in accreteinfosolution’s Appointment Buddy Widget plugin for WordPress. Any installation of the plugin with a version number through 1.2, including 1.2 and earlier, is affected. Upgrading to 1.3 or later eliminates the issue.

Risk and Exploitability

The CVSS base score of 7.1 denotes high severity; the EPSS score of less than 1 % indicates a currently low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need to embed malicious input that is reflected back to the browser, likely through a user‑visible field or URL parameter. Because the flaw does not require authentication, the attack vector is considered external and the scope is limited to the victim’s session. Nonetheless, the potential impact on confidentiality, integrity, and availability justifies prompt action.

Generated by OpenCVE AI on May 1, 2026 at 14:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Appointment Buddy Widget plugin to version 1.3 or newer, where the XSS flaw is fixed.
  • If an immediate upgrade is not possible, add a content‑security‑policy that blocks inline scripts on pages served by the plugin.
  • Configure the plugin or surrounding WordPress theme to perform strict output encoding and input validation on all data displayed by the widget, ensuring that any user‑supplied content is safely escaped before rendering.

Generated by OpenCVE AI on May 1, 2026 at 14:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5659 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in accreteinfosolution Appointment Buddy Widget allows Reflected XSS. This issue affects Appointment Buddy Widget: from n/a through 1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in accreteinfosolution Appointment Buddy Widget allows Reflected XSS. This issue affects Appointment Buddy Widget: from n/a through 1.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in accreteinfosolution Appointment Buddy Widget appointment-buddy-online-appointment-booking-by-accrete allows Cross-Site Scripting (XSS).This issue affects Appointment Buddy Widget: from n/a through <= 1.2.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in accreteinfosolution Appointment Buddy Widget allows Reflected XSS. This issue affects Appointment Buddy Widget: from n/a through 1.2.
Title WordPress Appointment Buddy Widget By Accrete plugin <= 1.2. - Reflected Cross-Site Scripting vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:35.337Z

Reserved: 2025-02-03T13:34:21.524Z

Link: CVE-2025-25099

cve-icon Vulnrichment

Updated: 2025-03-03T16:00:14.768Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:50.490

Modified: 2026-04-23T15:25:35.123

Link: CVE-2025-25099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:45:16Z

Weaknesses