Impact
The vulnerable plugin fails to neutralize user input when rendering pages, allowing reflected XSS. This flaw permits an attacker to embed JavaScript via URLs or forms that the site reflects back. The CVE description does not list specific impacts such as session cookie theft or credential phishing; however, these are inferred consequences of executing code in a victim’s browser.
Affected Systems
This issue affects the Awesome Event Booking plugin from AwesomeTOGI, version 2.8.4 and all earlier releases. No other products or versions are identified as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates medium‑to‑high risk for web applications that rely on this plugin. Although the EPSS score is reported as less than 1%, meaning a low probability of widespread exploitation, the absence from the KEV list does not remove the need for remediation. The CVE description states only that the plugin allows reflected XSS; the statement that an attacker would need to entice a victim to a specially crafted link or manipulate a form submission is inferred based on general XSS behavior.
OpenCVE Enrichment
EUVD