Impact
Improper neutralization of input during web page generation allows attackers to inject arbitrary scripts into the rendered page. The flaw is a DOM‑based XSS that can be triggered by malformed data that the Kalender.digital plugin accepts, making untrusted content executable in the victim’s browser. This can enable session hijacking, defacement, or the delivery of additional malware to users who visit affected pages.
Affected Systems
Kalender.digital, a WordPress plugin for the Kalender.online/Kalender.digital site, is affected in all releases up to and including version 1.0.13. Any WordPress instance using this plugin in that version range is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity; the EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The most likely exploitation path involves an attacker crafting a malicious URL or input that is processed by the plugin and reflected in the browser’s DOM. Users who click such links or view maliciously crafted content could experience script injection. While the likelihood is low, the impact on confidentiality, integrity, and availability for the affected site is significant if exploited.
OpenCVE Enrichment