Stored Cross-Site Scripting Vulnerability in Event RSVP and Simple Event Management Plugin for WordPress
CVE-2025-5540
What is CVE-2025-5540?
The Event RSVP and Simple Event Management Plugin for WordPress has a vulnerability allowing authenticated attackers with contributor-level access or higher to execute arbitrary scripts on affected pages. This weakness stems from inadequate input sanitization and output escaping related to the plugin's 'emd_mb_meta' shortcode, potentially leading to unauthorized data exposure and manipulation whenever users access the compromised pages.
Affected Version(s)
Event RSVP and Simple Event Management Plugin * <= 4.1.0
News Articles
Vulnerabilities | INCIBE-CERT | INCIBE
CVE-2025-5540 Publication date: 26/06/2025 The Event RSVP and Simple Event Management Plugin plugin for WordPress is vulnerable to Stored...
3 weeks ago
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
- 📰
First article discovered by INCIBE
Vulnerability published
Vulnerability Reserved