Impact
The vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject arbitrary JavaScript into pages generated by the plugin. When a script is saved within the course booking data, it is rendered on the front‑end without proper neutralization, allowing malicious code execution on any site visitor.
Affected Systems
This flaw affects the WordPress Plugin "Course Booking Platform" from the vendor Course Finder | andré martin - it solutions & research UG, specifically any instance using version 1.0.0 or earlier. All releases from the initial version through 1.0.0 are impacted, with no fix currently released.
Risk and Exploitability
The vulnerability carries a moderate CVSS score of 6.5. Its EPSS score is below 1 %, indicating a low likelihood of exploitation, and it is not listed in the CISA KEV catalog. The most likely attack vector is via the plugin's administrative interface, where a user with sufficient privileges can inject malicious code into stored course data that is then served to all visitors.
OpenCVE Enrichment
EUVD