Cross-Site Scripting Vulnerability in George Sexton WordPress Events Calendar Plugin
CVE-2025-58862

6.5MEDIUM

What is CVE-2025-58862?

The George Sexton WordPress Events Calendar Plugin – connectDaily is vulnerable to Cross-Site Scripting (XSS), allowing attackers to execute malicious scripts in the context of users who access the compromised pages. This vulnerability enables unauthorized users to inject malicious payloads into web page elements, potentially leading to data theft, session hijacking, or other malicious actions without the user’s consent. The affected versions of the plugin are from n/a through 1.5.3. It is essential for users to update their plugins to the latest version to mitigate this risk.

Affected Version(s)

WordPress Events Calendar Plugin – connectDaily <= 1.5.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mika (Patchstack Alliance)
.
CVE-2025-58862 : Cross-Site Scripting Vulnerability in George Sexton WordPress Events Calendar Plugin