Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in useStrict UseStrict's Calendly Embedder cal-embedder-lite allows Stored XSS.This issue affects UseStrict's Calendly Embedder: from n/a through <= 1.1.7.2.
Published: 2025-12-09
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored Cross‑Site Scripting flaw that allows attackers to inject malicious scripts into the output of a WordPress page that uses the UseStrict Calendly Embedder plugin. The flaw arises from improper input neutralization during web page generation, meaning data entered into the plugin can be persisted and later executed in the browser context of any user who views the affected page. The impact is that an attacker could run arbitrary JavaScript, potentially stealing credentials, session cookies, or defacing site content for any visitor to the site.

Affected Systems

The affected product is the WordPress UseStrict Calendly Embedder plugin from UseStrict, specifically all releases from the earliest available version up through and including 1.1.7.2. WordPress administrators running this plugin in any installation are susceptible. No specific WordPress core version is required for the flaw to exist, but the plugin must be present and configured in the site environment.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% points to a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not been observed in known exploit campaigns. Attackers would likely need the ability to submit or modify content through the plugin interface, so the attack vector is essentially a stored XSS through administrative or user‑generated input. Given the medium severity and low exploitation likelihood, sites with the affected plugin should quietly monitor for suspicious activity while prioritizing remediation.

Generated by OpenCVE AI on April 29, 2026 at 22:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest version of UseStrict's Calendly Embedder, ensuring it is newer than 1.1.7.2.
  • If an update is not immediately available, disable or remove the plugin until a patched version is released, or restrict access to the configuration interface so only trusted administrators can edit plugin data.
  • If updating or disabling is not feasible, configure the site’s Content Security Policy to block inline scripts from the plugin’s output, reducing the risk of XSS exploitation.

Generated by OpenCVE AI on April 29, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in useStrict UseStrict&#039;s Calendly Embedder cal-embedder-lite allows Stored XSS.This issue affects UseStrict&#039;s Calendly Embedder: from n/a through <= 1.1.7.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in useStrict UseStrict's Calendly Embedder cal-embedder-lite allows Stored XSS.This issue affects UseStrict's Calendly Embedder: from n/a through <= 1.1.7.2.

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 10 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in useStrict UseStrict&#039;s Calendly Embedder cal-embedder-lite allows Stored XSS.This issue affects UseStrict&#039;s Calendly Embedder: from n/a through <= 1.1.7.2.
Title WordPress UseStrict's Calendly Embedder plugin <= 1.1.7.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:21.160Z

Reserved: 2025-12-09T12:21:23.942Z

Link: CVE-2025-67555

cve-icon Vulnrichment

Updated: 2025-12-10T21:40:07.038Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:31.753

Modified: 2026-04-28T19:35:35.487

Link: CVE-2025-67555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:00:14Z

Weaknesses