Impact
The Easy Appointments plugin fails to neutralize user supplied data before rendering it in the browser, creating a DOM‑based Cross‑Site Scripting flaw. An attacker can embed malicious JavaScript via crafted input or URLs. When a victim views a page that includes affected plugin output, the injected script runs in the victim’s browser in the context of the site, enabling cookie theft, session hijacking, data exfiltration, or malicious redirects.
Affected Systems
Any WordPress site that has the Easy Appointments plugin version 4.0.2.1 or earlier is vulnerable. The flaw exists in every release from the earliest available plugin versions up through 4.0.2.1.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact on web‑interface confidentiality and integrity. EPSS is not available and the vulnerability is not listed in KEV, suggesting limited known exploitation. The attack can be carried out from a remote malicious link or crafted form input; the attacker does not need privileged access or RCE, but a victim must view the affected page for the payload to execute.
OpenCVE Enrichment