Impact
The vulnerability allows unauthenticated users to inject arbitrary JavaScript into the Events Made Easy plugin’s output, resulting in client‑side cross‑site scripting. An attacker could cause a site visitor’s browser to execute malicious code, potentially enabling session hijacking, credential theft, or the launch of additional attacks from the compromised client.
Affected Systems
WordPress plugin ‘Events Made Easy’ from Franky, affecting all installations running version 3.2.5 or earlier. The flaw is present in any site that has the vulnerable plugin enabled.
Risk and Exploitability
The CVSS base score of 7.1 reflects a high impact of this client‑side flaw. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the issue is unauthenticated, any visitor to the affected WordPress site can trigger the injection by supplying a crafted request through the plugin’s interface. The combination of a high impact score and the lack of access control makes the risk significant until the plugin is updated.
OpenCVE Enrichment