Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Event Espresso – Custom Email Template Shortcode email-shortcode allows Reflected XSS.This issue affects Event Espresso – Custom Email Template Shortcode: from n/a through <= 1.0.0.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of user-supplied input during the generation of a web page, enabling a reflected cross‑site scripting (XSS) flaw. An attacker can craft a request containing malicious script code that is returned in the page rendered by the Event Espresso – Custom Email Template Shortcode plugin. When a victim requests such a page, the embedded script executes in the victim’s browser, potentially allowing the attacker to steal session cookies, redirect the user to malicious sites, or inject harmful content.

Affected Systems

The flaw affects WordPress installations that use the Event Espresso – Custom Email Template Shortcode plugin authored by Aakif Kadiwala, version 1.0.0 and earlier. No other versions are known to be vulnerable according to the current advisory.

Risk and Exploitability

The CVSS score of 7.1 denotes a high impact potential, while the EPSS score of &lt;1 % suggests that only a small fraction of the overall deployment is likely to be actively exploited at any given time. The plugin processes user input that is subsequently reflected in the HTML output, so the attacker’s vector is a web‑based request that can be triggered remotely by any user. Because the vulnerability is not listed in the CISA KEV catalog, there is no documented exploitation yet. Based on the description, the likely attack vector is an attacker‑controlled input via a crafted URL or form that the plugin then exposes unescaped in the page.

Generated by OpenCVE AI on April 30, 2026 at 21:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Event Espresso – Custom Email Template Shortcode plugin to a version newer than 1.0.0.
  • If an upgrade cannot be applied immediately, disable the shortcode or the entire plugin until a patched version is available.
  • Configure a web application firewall or content‑security‑policy rules to block reflected XSS attempts targeting the plugin’s input parameters.

Generated by OpenCVE AI on April 30, 2026 at 21:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11652 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Event Espresso – Custom Email Template Shortcode allows Reflected XSS. This issue affects Event Espresso – Custom Email Template Shortcode: from n/a through 1.0.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Event Espresso – Custom Email Template Shortcode allows Reflected XSS. This issue affects Event Espresso – Custom Email Template Shortcode: from n/a through 1.0.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Event Espresso – Custom Email Template Shortcode email-shortcode allows Reflected XSS.This issue affects Event Espresso – Custom Email Template Shortcode: from n/a through <= 1.0.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Event Espresso – Custom Email Template Shortcode allows Reflected XSS. This issue affects Event Espresso – Custom Email Template Shortcode: from n/a through 1.0.0.
Title WordPress Event Espresso plugin <= 1.0.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:23.203Z

Reserved: 2025-04-09T11:19:28.417Z

Link: CVE-2025-32507

cve-icon Vulnrichment

Updated: 2025-04-17T18:05:17.159Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:39.863

Modified: 2026-04-23T15:29:00.550

Link: CVE-2025-32507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T21:45:26Z

Weaknesses