Impact
The Holiday Calendar plugin includes a stored XSS flaw that occurs when user‑supplied data is not properly neutralized before being rendered on the site. An attacker can submit crafted input that is later displayed to any visitor, leading to the execution of arbitrary scripts in the victim’s browser. This could enable session hijacking, theft of authentication credentials, manipulation of page content, or the execution of further malicious payloads as the affected user. The weakness is classified as CWE‑79, indicating an injection issue that fails to perform adequate input validation or output encoding.
Affected Systems
WordPress sites running The Holiday Calendar plugin version 1.18.2.1 or earlier are vulnerable. The plugin is distributed by mva7 under the name "The Holiday Calendar" and is compatible with standard WordPress installations.
Risk and Exploitability
The CVSS score of 6.5 marks this as a moderate‑severity issue. The EPSS score of less than 1% suggests the likelihood of exploitation at present is low, and the vulnerability is not listed in the CISA KEV database. Attackers can leverage the flaw by creating or editing content within the plugin, typically requiring administrative or content‑author privileges. Once malicious content is stored, any user who views the affected page will have the script executed in their own browser context.
OpenCVE Enrichment
EUVD