Impact
The Eventin plugin for WordPress allows an authenticated user with contributor-level access or higher to submit arbitrary text in the 'etn_shedule_objective' schedule_slot field without applying any sanitization or escaping. Because the input is stored in the database and later rendered on pages that display the schedule slot, the contained JavaScript code is executed in the victim’s browser whenever a page that includes the schedule slot is accessed.
Affected Systems
WordPress sites that have installed the Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin version 4.1.23 or earlier are susceptible to this flaw. Any site running a vulnerable plugin instance, regardless of additional configurations, is affected as long as the attacker can attain contributor or higher privileges.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate impact, while the EPSS score of < 1 % suggests that the likelihood of exploitation is low in the short term. The vulnerability is not listed in the CISA KEV catalogue. Attack requires authenticated access with contributor‑level permissions or above; once the malicious payload is stored, it is executed for any user who views the affected page, but there is no non‑authenticated or network‑level attack vector outlined in the description.
OpenCVE Enrichment