Impact
The CVE identifies a Cross‑Site Request Forgery (CSRF) flaw in the Steve Availability Calendar plugin that permits an attacker to store malicious JavaScript payloads on the server. When any user views the affected calendar entry, the stored script will execute in the victim’s browser. The description does not detail the specific client‑side consequences, but typical stored XSS can lead to theft of credentials, session hijacking, or other client‑side attacks once the script runs.
Affected Systems
WordPress sites that deploy the Steve Availability Calendar plugin version 0.2.4 or earlier are impacted. The vulnerability applies from the earliest release of the plugin through version 0.2.4, regardless of other site patches.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity, yet the EPSS score of less than 1% indicates a low probability of exploitation, and it is not present in CISA’s KEV catalog. The attack vector is inferred to be a CSRF request originating from a malicious web page that a logged‑in user unintentionally visits; by sending a crafted request, an attacker can persist a malicious script. While the likelihood of exploitation is low, the high severity necessitates timely remediation.
OpenCVE Enrichment
EUVD