VYPR
Medium severity6.5NVD Advisory· Published Jun 27, 2025· Updated Apr 23, 2026

CVE-2025-53294

CVE-2025-53294

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Smart Agenda Smart Agenda smart-agenda-prise-de-rendez-vous-en-ligne allows Stored XSS.This issue affects Smart Agenda: from n/a through <= 4.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Smart Agenda plugin (≤4.9) allows attackers with contributor-level access to inject malicious scripts viewed by other users.

Vulnerability

Analysis

The Smart Agenda plugin for WordPress, versions through 4.9, contains a stored cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This flaw resides in the smart-agenda-prise-de-rendez-vous-en-ligne plugin and is classified as a Stored XSS vulnerability [1].

Attack

Vector and Exploitation

To exploit this vulnerability, an attacker must have at least contributor-level access to the WordPress site [1]. The attacker can inject malicious scripts into fields that are later displayed to other users, such as appointment data or other plugin-generated content. Successful exploitation requires the victim (an administrator or visitor) to interact with the crafted page, for example by viewing an appointment or clicking a link [1].

Impact

An attacker can inject arbitrary JavaScript or HTML payloads, which may result in redirects, unwanted advertisements, or theft of session cookies [1]. This could lead to further compromise of the affected site, including privilege escalation if an administrator's session is hijacked.

Mitigation

The vendor has released version 5.0, which fixes the vulnerability [1]. Users are strongly advised to update immediately. For those unable to update, Patchstack recommends enabling auto-updates or contacting their hosting provider for assistance [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.