Impact
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress contains a stored cross‑site scripting flaw that is triggered by the etn_faq_content parameter. With contributor‑level access or higher, an authenticated; the payload is stored and later rendered on event detail pages without proper escaping. When visitors load the affected page, the malicious script executes in their browsers, allowing the attacker to run arbitrary code in the context of each user who views the page.
Affected Systems
WordPress sites that have installed the Eventin plugin at version 4.1.15 or older are impacted. The vulnerability exists in all releases up to and including 4.1.15, specifically within the FAQ management portion where etn_faq_content is accepted.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, indicating a moderate level of severity. The EPSS score is less than 1%, implying a low likelihood of exploitation in the wild, and it is not listed in the CISA KEV database. The attack vector is a stored cross‑site scripting attack that requires the attacker to be authenticated with contributor or higher privileges before injecting malicious code that is subsequently executed on every visitor's browser when the event page is accessed.
OpenCVE Enrichment