Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart Agenda smart-agenda-prise-de-rendez-vous-en-ligne allows Stored XSS.This issue affects Smart Agenda: from n/a through <= 4.9.
Published: 2025-06-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Smart Agenda WordPress plugin contains an Improper Neutralization of Input During Web Page Generation flaw that allows Stored Cross‑Site Scripting. When attackers insert crafted script content into plugin fields, that content is stored in the database and later rendered unescaped inside web pages, potentially executing arbitrary code in the browser of any visitor. This can lead to session hijacking, credential theft, or theft of confidential data disclosed to the user. The weakness is classified as CWE‑79.

Affected Systems

The vulnerability exists in the Smart Agenda plugin distributed with WordPress, affecting all releases from the initial version up to and including 4.9. Any WordPress site running this plugin and not upgraded bypasses the fix.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk, and the EPSS score of less than 1% suggests a low likelihood of public exploitation at this moment. The vulnerability is not listed in the CISA KEV catalog, so no known mass exploitation is reported. Attackers can exploit the issue by creating malicious content that the plugin stores and later displays, typically via the plugin’s administration interface. Successful exploitation requires access to the plugin’s data entry interface, which may be restricted to site administrators or trusted users.

Generated by OpenCVE AI on April 30, 2026 at 10:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Smart Agenda to the latest version that removes the XSS flaw.
  • If an upgrade is not immediately possible, disable the plugin or remove the managed content features that allow user input.
  • Apply a general input sanitization rule to any user‑generated content before rendering, ensuring proper escaping of output.

Generated by OpenCVE AI on April 30, 2026 at 10:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19407 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart Agenda allows Stored XSS. This issue affects Smart Agenda: from n/a through 4.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart Agenda allows Stored XSS. This issue affects Smart Agenda: from n/a through 4.9. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart Agenda smart-agenda-prise-de-rendez-vous-en-ligne allows Stored XSS.This issue affects Smart Agenda: from n/a through <= 4.9.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 27 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Jun 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart Agenda allows Stored XSS. This issue affects Smart Agenda: from n/a through 4.9.
Title WordPress Smart Agenda plugin <= 4.9 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:22.847Z

Reserved: 2025-06-27T11:58:59.925Z

Link: CVE-2025-53294

cve-icon Vulnrichment

Updated: 2025-06-27T14:34:00.501Z

cve-icon NVD

Status : Deferred

Published: 2025-06-27T14:15:51.143

Modified: 2026-04-23T15:32:26.533

Link: CVE-2025-53294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T10:15:34Z

Weaknesses