Impact
The CVE describes an improper neutralization of input during web page generation, resulting in a stored cross‑site scripting vulnerability in Simpma Embed Calendly. An attacker may be able to inject malicious scripts that are saved and later executed in the context of a user’s browser, potentially compromising user data and session integrity.
Affected Systems
WordPress plugin Simpma:Embed Calendly, any release up to and including version 4.4 is affected; versions newer than 4.4 are not impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the near future. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker submitting malicious content that is stored by the plugin and later rendered to other users. These statements are inferred from the description where the attack vector is not explicitly stated.
OpenCVE Enrichment