Cross-Site Scripting Vulnerability in Easy Appointments by Easy Appointments
CVE-2025-49398

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2025

What is CVE-2025-49398?

The Easy Appointments plugin for WordPress is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper neutralization of script-related HTML tags. This flaw allows attackers to inject malicious code, potentially compromising user interactions and leading to unauthorized actions on affected sites running versions up to 3.12.14. It is crucial for users to upgrade their plugins promptly to mitigate any security risks associated with this vulnerability.

Affected Version(s)

Easy Appointments <= n/a

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Najib Sinjari | Patchstack Bug Bounty Program
.