VYPR
High severity7.1NVD Advisory· Published May 19, 2025· Updated Apr 23, 2026

CVE-2025-39372

CVE-2025-39372

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplus allows Reflected XSS.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through <= 2.6.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in WordPress Events Calendar Registration & Tickets plugin up to 2.6.0 allows injection of malicious scripts via crafted input.

The WordPress Events Calendar Registration & Tickets plugin (wpeventplus) versions up to and including 2.6.0 contain a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of user input during web page generation [1]. This flaw occurs when the plugin fails to sanitize or escape input before reflecting it in the response, allowing an attacker to embed arbitrary scripts in a crafted link.

Exploitation requires user interaction — a victim must click a specially crafted link or visit a maliciously prepared page [1]. While the vulnerability can be initiated by low-privileged roles, successful execution depends on a privileged user performing an action, such as clicking the link or submitting a form [1]. No authentication is needed from the attacker to generate the malicious payload.

If exploited, an attacker can inject malicious scripts (e.g., redirects, advertisements, or other HTML payloads) into the affected website. These scripts execute in the context of the victim's browser, potentially leading to data theft, session hijacking, or defacement [1]. The CVSS v3 base score is 7.1, reflecting moderate danger and a risk of mass exploitation [1].

As of publication, the vendor has not released an official patch, but Patchstack has issued a mitigation rule to block attacks [1]. Users are strongly advised to update the plugin as soon as a fixed version becomes available. If updating is not possible, consider contacting the hosting provider or web developer for assistance [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.