Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in George Sexton WordPress Events Calendar Plugin – connectDaily connect-daily-web-calendar allows Stored XSS.This issue affects WordPress Events Calendar Plugin – connectDaily: from n/a through <= 1.5.5.
Published: 2025-09-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can exploit the WordPress Events Calendar Plugin – connectDaily by inserting malicious script content that the plugin fails to neutralize before rendering a page. When an authorized user submits the injected payload through the plugin interface, the content is saved to the database and subsequently displayed to all site visitors, resulting in a stored cross‑site scripting vulnerability. The impact is that anyone who views the affected page could have malicious code executed in their browser, potentially leading to credential theft, session hijacking, or defacement of the site’s content.

Affected Systems

The vulnerability affects the WordPress Events Calendar Plugin – connectDaily, version 1.5.5 and earlier. The plugin is developed by George Sexton and is commonly used to integrate web calendars into WordPress sites. Users running any of the affected releases are at risk, regardless of additional security measures deployed elsewhere.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, primarily driven by the impact on integrity and confidentiality via XSS. The EPSS score is reported as less than 1 %, suggesting very low exploitation probability at the time of assessment. The vulnerability is not listed in CISA’s KEV catalog, which further lowers the likelihood of widespread exploitation. The likely attack vector appears to be an authenticated user with access to the plugin’s administration or input areas, as inferred from the description. The CVSS score suggests moderate severity, but the exploitation probability remains very low.

Generated by OpenCVE AI on April 30, 2026 at 07:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WordPress Events Calendar Plugin – connectDaily to a release newer than 1.5.6.
  • If the upgrade is not possible, disable the plugin until a patched version is available.
  • Implement a Content Security Policy that restricts script execution or deploy an XSS filtering plugin as an interim safeguard.

Generated by OpenCVE AI on April 30, 2026 at 07:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26915 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in George Sexton WordPress Events Calendar Plugin – connectDaily allows Stored XSS. This issue affects WordPress Events Calendar Plugin – connectDaily: from n/a through 1.5.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in George Sexton WordPress Events Calendar Plugin – connectDaily allows Stored XSS. This issue affects WordPress Events Calendar Plugin – connectDaily: from n/a through 1.5.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in George Sexton WordPress Events Calendar Plugin – connectDaily connect-daily-web-calendar allows Stored XSS.This issue affects WordPress Events Calendar Plugin – connectDaily: from n/a through <= 1.5.5.
Title WordPress WordPress Events Calendar Plugin – connectDaily Plugin <= 1.5.3 - Cross Site Scripting (XSS) Vulnerability WordPress WordPress Events Calendar Plugin – connectDaily Plugin <= 1.5.5 - Cross Site Scripting (XSS) Vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 05 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in George Sexton WordPress Events Calendar Plugin – connectDaily allows Stored XSS. This issue affects WordPress Events Calendar Plugin – connectDaily: from n/a through 1.5.3.
Title WordPress WordPress Events Calendar Plugin – connectDaily Plugin <= 1.5.3 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-13T00:17:35.853Z

Reserved: 2025-09-05T10:49:57.447Z

Link: CVE-2025-58862

cve-icon Vulnrichment

Updated: 2025-09-05T14:38:13.545Z

cve-icon NVD

Status : Deferred

Published: 2025-09-05T14:16:01.933

Modified: 2026-04-23T15:33:46.843

Link: CVE-2025-58862

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T07:15:31Z

Weaknesses