Impact
The Calendar Plus WordPress plugin implements page rendering without properly neutralizing user‑supplied input, allowing a reflected cross‑site scripting flaw. It is inferred that an attacker could embed malicious JavaScript in the plugin’s output, which would execute in the browsers of users who view affected pages.
Affected Systems
The vulnerability affects any WordPress installation running the webjunk Calendar Plus plugin version 1.2.4 or earlier. All releases up to and including 1.2.4 are susceptible.
Risk and Exploitability
The CVSS score of 7.1 places the issue in the high‑severity range. An EPSS score of less than 1% indicates a low probability of exploitation. The flaw is not listed in the CISA KEV catalog, so no large‑scale attacks have been reported. It is inferred that exploitation would require delivery of a crafted request that includes malicious input in a calendar parameter, after which the XSS payload is reflected back to the victim’s browser. It is also inferred that no authentication or elevated privileges are necessary for exploitation.
OpenCVE Enrichment