Impact
A Cross‑Site Request Forgery (CSRF) vulnerability exists in the WordPress Events Calendar Plugin – connectDaily. An attacker can craft a request that the plugin processes without proper CSRF validation, allowing arbitrary JavaScript to be injected. The injected code executes in the victim’s browser when the site’s pages are rendered, enabling attackers to exfiltrate credentials, deface content, or redirect users to malicious domains.
Affected Systems
WordPress sites that use the WordPress Events Calendar Plugin – connectDaily version 1.5.4 or earlier, including all earlier releases, are affected. The flaw exists from the initial release of the plugin through to the specified limit.
Risk and Exploitability
The CVSS score of 7.1 signifies high severity, while the EPSS score of <1% indicates a low probability of exploitation in the current threat landscape. The vulnerability is not listed in CISA KEV. Exploitation would most likely involve an attacker hosting a malicious webpage that persuades a legitimate user to trigger a crafted CSRF request, resulting in the injection of payloads that run in the context of the site.
OpenCVE Enrichment
EUVD