Impact
The WP-CalDav2ICS plugin version 1.3.4 or earlier allows a Cross‑Site Request Forgery attack that can lead to stored Cross‑Site Scripting. An attacker who can trick an authenticated administrator into performing a specific request can inject JavaScript that will be rendered on subsequent page views, potentially compromising site integrity and user data.
Affected Systems
The vulnerability affects the WordPress plugin WP‑CalDav2ICS from vendor hoernerfranz, version 1.3.4 and earlier. Systems running these or older releases are susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high impact, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Attackers would likely exploit the flaw by sending a forged HTTP request to the plugin’s endpoint from a victim’s browser, often leveraging social‑engineering or compromised credentials.
OpenCVE Enrichment