Impact
Spiffy Plugin for WordPress, versions prior to 5.0.9, contains a stored cross‑site scripting flaw in the Event Title field. The flaw can be leveraged by an authenticated user with the contributor role to inject arbitrary scripts, which may redirect victims to malicious sites or gain control of their WordPress accounts. The vulnerability is a classic reflected injection stored in application data that is later executed in the browser context.
Affected Systems
Any WordPress installation running Spiffy Plugin v5.0.8 or earlier is affected. The plugin is distributed through the WordPress plugin repository and may be present under any site using event management via Spiffy.
Risk and Exploitability
Because the attack requires only a legitimate contributor account, the initial barrier is low. Once an attacker injects a malicious payload, the impact is high: users who view the compromised event will execute the injected code. Although EPSS data is not available and the CVE is not listed in CISA KEV, the nature of stored XSS combined with authenticated exploitation points to a high risk of compromise. Attackers would need access to the WordPress admin interface to create or modify events; therefore, the threat vector is internal to the WordPress installation.
OpenCVE Enrichment