Impact
The Quick Event Manager plugin for WordPress contains an unauthenticated Cross‑Site Scripting flaw that allows an attacker to inject arbitrary scripts into pages generated by the plugin. This vulnerability permits the execution of attacker‑supplied code in the browser context of anyone who views the affected pages.
Affected Systems
The BrightVesselDevelopment Quick Event Manager plugin for WordPress, versions 9.17 and earlier, is susceptible to the flaw. Any WordPress site that continues to run an affected version is exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is not available and the flaw is not in CISA KEV, but the attack can be performed without authentication, simply by accessing the plugin’s pages with a crafted payload. This makes exploitation straightforward with standard XSS techniques.
OpenCVE Enrichment