Impact
The vulnerability allows an attacker to inject arbitrary client‑side code that is stored within the EventON plugin and then served to users who view the affected pages. This stored XSS can lead to session hijacking, defacement, or the execution of malicious scripts in the context of other site visitors, thereby compromising confidentiality, integrity, and availability of web content. The weakness is identified as Improper Neutralization of Input During Web Page Generation (CWE‑79).
Affected Systems
WordPress sites that use the EventON plugin version 4.9.12 or earlier. The plugin is authored by ashanjay (EventON) and is available in any WordPress installation where it has not yet been upgraded beyond this version threshold.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests that current exploitation activity is unlikely, yet the vulnerability is exploitable in any WordPress environment that still hosts the affected plugin. The attack vector is inferred to be HTTP requests that submit event data containing unsanitized script payloads, which are then rendered to other users when the event is displayed. The vulnerability is not listed in the CISA KEV catalog, but administrators should still treat it as a potential threat due to the web‑based nature of the flaw.
OpenCVE Enrichment