Cross-Site Scripting Vulnerability in George Sexton WordPress Events Calendar Plugin
CVE-2025-58862
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2025
What is CVE-2025-58862?
The George Sexton WordPress Events Calendar Plugin – connectDaily is vulnerable to Cross-Site Scripting (XSS), allowing attackers to execute malicious scripts in the context of users who access the compromised pages. This vulnerability enables unauthorized users to inject malicious payloads into web page elements, potentially leading to data theft, session hijacking, or other malicious actions without the user’s consent. The affected versions of the plugin are from n/a through 1.5.3. It is essential for users to update their plugins to the latest version to mitigate this risk.
Affected Version(s)
WordPress Events Calendar Plugin – connectDaily <= 1.5.3