Impact
Improper neutralization of user input in the StellarWP Event Tickets plugin allows an attacker to inject malicious scripts that are echoed back to the browser. This can lead to session hijacking, cookie theft, defacement or other hostile actions performed in the victim’s context. The flaw is a classic input‑validation weakness (CWE‑79).
Affected Systems
WordPress sites that use the StellarWP Event Tickets plugin with a version of 5.20.0 or earlier are affected. Any installation that includes this plugin runs the risk of reflected XSS if user input is displayed without proper escaping.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating a high impact. The EPSS score is under 1%, so exploitation attempts are currently rare. This CVE is not listed in the CISA KEV catalog. Exploitation is feasible via a crafted URL or form input that contains a malicious payload; the attacker does not need privileged access, merely a way to lead an end‑user to the crafted link.
OpenCVE Enrichment
EUVD