Impact
This vulnerability arises because the Lockme calendars integration plugin stores configuration values without sanitizing or escaping them. An authenticated user with administrator privileges can enter malicious content into fields such as App ID, App Secret, Bookings ID prefix, and API domain. When the settings page is rendered, that content allows the payload to execute as JavaScript whenever the page is viewed by any user who has access to the administration area, falling under CWE‑79.
Affected Systems
WordPress installations that have the Lockme calendars integration plugin developed by lustmored and running any version up to and including 2.11.0. The data does not indicate whether newer releases contain a fix, so any site using these versions remains vulnerable.
Risk and Exploitability
The CVSS score of 4.4 and an EPSS of less than 1 % classify this issue as moderate risk with a low likelihood of exploitation. An attacker must first possess or compromise administrator‑level credentials to inject the payload, and the script only runs when users view the settings page. The flaw is not listed in CISA’s KEV catalog, and no public exploits have been documented.
OpenCVE Enrichment