Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation flaw that allows a reflected Cross‑Site Scripting (XSS) attack. A malicious user can supply crafted input that is incorporated into a page response without proper escaping, enabling the execution of arbitrary JavaScript in the victim’s browser. This can lead to session hijacking, defacement, or the delivery of phishing content, all of which compromise user confidentiality and integrity.
Affected Systems
WordPress sites that use the abelony Events Planner plugin version 1.3.10 or earlier are affected. The issue applies to any installation where the vulnerable plugin is active, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 7.1 classifies this issue as High severity, but its EPSS score is under 1%, indicating a low probability of exploitation at present. The vulnerability requires a user to visit or interact with a crafted URL or form that contains the unsanitized input, meaning the threat vector is remote but user‑dependent. Because it is not listed in the CISA KEV catalog, there is no evidence of active exploitation, yet the potential impact warrants prompt remediation.
OpenCVE Enrichment
EUVD