Impact
The flaw is an instance of improper neutralization of input during web page generation, resulting in a DOM‑based XSS vulnerability. An attacker can supply specially crafted data that, when rendered by the Themify Event Post plugin, can be interpreted by the victim’s browser as executable script. This permits the execution of malicious code in the context of the site, potentially leading to credential theft session hijacking, or defacement.
Affected Systems
In the WordPress plugin "Themify Event Post", all releases up to and including 1.3.2 are impacted. Sites running any of those versions are at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating moderate severity, and an EPSS score of less than 1%, suggesting a low likelihood of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector involves a malformed input or URL parameter that is reflected in the DOM by the plugin.
OpenCVE Enrichment
EUVD