Stored Cross-Site Scripting Vulnerability in Event RSVP and Simple Event Management Plugin for WordPress
CVE-2025-5540
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 June 2025
What is CVE-2025-5540?
The Event RSVP and Simple Event Management Plugin for WordPress has a vulnerability allowing authenticated attackers with contributor-level access or higher to execute arbitrary scripts on affected pages. This weakness stems from inadequate input sanitization and output escaping related to the plugin's 'emd_mb_meta' shortcode, potentially leading to unauthorized data exposure and manipulation whenever users access the compromised pages.
Affected Version(s)
Event RSVP and Simple Event Management Plugin * <= 4.1.0