Stored Cross-Site Scripting Vulnerability in Digital Events Calendar Plugin for WordPress
CVE-2025-5801
6.4MEDIUM
What is CVE-2025-5801?
The Digital Events Calendar plugin for WordPress is subject to a stored cross-site scripting vulnerability that allows attackers with Contributor-level access or higher to inject malicious web scripts. This is due to a lack of sufficient input sanitization and output escaping in the 'column' parameter, which leaves users exposed to potential script executions when they access affected pages. Users of this plugin should update to the latest version to mitigate security risks associated with this vulnerability.
Affected Version(s)
Digital Events Calendar * <= 1.0.8