Impact
The Event post WordPress plugin implements an input field that is stored without proper sanitization, creating a stored Cross‑Site Scripting vulnerability. An attacker can insert malicious JavaScript that is later served to any visitor of the affected site. In the victim’s browser the injected code runs with the privileges of the site, allowing session hijacking, defacement, or the loading of additional malicious payloads. The weakness is identified as CWE‑79.
Affected Systems
All installations of Bastien Ho Event post plugin up to and including version 5.10.1 are affected. Sites running WordPress with this plugin version and not yet upgraded to a newer release are vulnerable regardless of other security controls.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact, and the EPSS score of less than 1% shows that the probability of exploitation in the wild is currently low. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely reach the vulnerable input through the plugin’s interface, meaning that unauthenticated or authenticated users of the website could trigger exploitation. The risk remains significant for users who rely on the plugin for event management, especially if the site accepts input from untrusted users.
OpenCVE Enrichment
EUVD