Impact
The vulnerability is a DOM‑Based Cross‑Site Scripting flaw that allows an attacker to inject arbitrary JavaScript into pages served by WordPress when the Event Feed for Eventbrite plugin is active. The injected script runs in the victim’s browser with the same privileges that user holds, which could be used to capture session cookies, alter page content, or exfiltrate sensitive information. This potential impact is inferred from the nature of DOM‑Based XSS, as the formal CVE description does not specify the exact consequences.
Affected Systems
The flaw affects the WordPress plugin Event Feed for Eventbrite developed by Bohemia Plugins for all versions up to and including 1.3.2. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% shows a currently low likelihood of exploitation. It is not catalogued in the CISA KEV list. Exploitation requires the attacker to deliver a malicious payload to a susceptible user’s browser, typically by linking to an affected page or embedding a crafted URL, which is a user‑interaction dependent scenario. The vulnerability does not provide remote code execution or privilege escalation beyond the victim’s user rights.
OpenCVE Enrichment
EUVD