Impact
Improper neutralization of user input in the Room 34 Creative Services, LLC WordPress ics‑calendar plugin allows an attacker to embed malicious script code into reflected responses. This reflected cross‑site scripting flaw can execute within the context of any visitor who loads a specially crafted URL, enabling theft of session cookies, credential harvesting, or malicious defacement. The weakness corresponds to CWE‑79 and does not provide server‑side code execution.
Affected Systems
All installations of the WordPress ics‑calendar plugin running version 12.1.1 or earlier are vulnerable. The plugin is distributed by Room 34 Creative Services, LLC and included in WordPress sites that have not upgraded beyond 12.1.1.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating high severity. The EPSS score is below 1 %, suggesting exploitation is unlikely but possible. The feature is not listed in CISA’s KEV catalog, and no public exploits are known. Attackers would need to entice a legitimate user to visit a crafted URL that includes malicious payload; based on the description, it is inferred that user interaction is required for exploitation.
OpenCVE Enrichment