Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx WPCal.io wpcal allows DOM-Based XSS.This issue affects WPCal.io: from n/a through <= 0.9.5.9.
Published: 2025-12-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WPCal.io plugin contains an improper neutralization of user input during web page generation, resulting in a DOM‑Based Cross‑Site Scripting (XSS) flaw as classified by CWE‑79. This weakness allows a malicious actor to inject and execute arbitrary JavaScript in the context of a victim’s browser when they visit or interact with affected plugin pages. The execution environment is client side, meaning that the injected code runs with the privileges of the visiting user and could potentially read user cookies, manipulate page content, or redirect traffic.

Affected Systems

Any installation of the WordPress revmakx WPCal.io plugin version 0.9.5.9 or earlier is vulnerable. The issue applies to all releases from the earliest available version through 0.9.5.9, so sites using older or legacy releases are also at risk. No other WordPress core components or unrelated plugins are impacted by this vulnerability.

Risk and Exploitability

The CVSS base score of 6.5 signifies a moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying that no widespread active exploitation has been reported. Exploitation requires a crafted request or input that reaches the plugin’s DOM handling code, typically achieved by an attacker sending a malicious link to a target user. Because the vector is client‑side, the attack relies on a victim’s interaction with the affected page. Overall, the risk remains moderate, but practical exploitation appears unlikely right now.

Generated by OpenCVE AI on April 30, 2026 at 04:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WPCal.io plugin to a version that includes the XSS fix, such as any release newer than 0.9.5.9.
  • If an upgrade cannot be performed immediately, enforce a strict Content Security Policy that blocks inline scripting or limits script execution to trusted origins to mitigate the risk of payload execution on affected pages.
  • Consider disabling or removing the WPCal.io plugin from the site temporarily until the vendor releases a patched version, ensuring that non‑essential functionality relying on the plugin is no longer exposed.

Generated by OpenCVE AI on April 30, 2026 at 04:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Revmakx WPCal.Io allows DOM-Based XSS.This issue affects WPCal.Io: from n/a through 0.9.5.9. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx WPCal.io wpcal allows DOM-Based XSS.This issue affects WPCal.io: from n/a through <= 0.9.5.9.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 30 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 17:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Revmakx WPCal.Io allows DOM-Based XSS.This issue affects WPCal.Io: from n/a through 0.9.5.9.
Title WordPress WPCal.io plugin <= 0.9.5.9 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:17.060Z

Reserved: 2025-11-21T11:21:20.344Z

Link: CVE-2025-66103

cve-icon Vulnrichment

Updated: 2025-12-30T19:24:05.776Z

cve-icon NVD

Status : Deferred

Published: 2025-12-30T17:15:43.210

Modified: 2026-04-23T15:35:22.823

Link: CVE-2025-66103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T04:45:06Z

Weaknesses