Cross-Site Scripting Vulnerability in George Sexton WordPress Events Calendar Plugin
CVE-2025-58862
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2025
What is CVE-2025-58862?
The George Sexton WordPress Events Calendar Plugin โ connectDaily is vulnerable to Cross-Site Scripting (XSS), allowing attackers to execute malicious scripts in the context of users who access the compromised pages. This vulnerability enables unauthorized users to inject malicious payloads into web page elements, potentially leading to data theft, session hijacking, or other malicious actions without the userโs consent. The affected versions of the plugin are from n/a through 1.5.3. It is essential for users to update their plugins to the latest version to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WordPress Events Calendar Plugin โ connectDaily <= 1.5.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved