Stored Cross-Site Scripting Vulnerability in Appointmind Plugin by WordPress
CVE-2025-9851
5.4MEDIUM
What is CVE-2025-9851?
The Appointmind plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability via its 'appointmind_calendar' shortcode. This flaw, present in all versions up to and including 4.1.0, results from inadequate input sanitization and output escaping on attributes provided by users. As a consequence, authenticated users with contributor-level access and higher are able to inject malicious scripts into pages. These scripts can be executed in the browser of any user who accesses the compromised pages, posing a significant security risk.
Affected Version(s)
Appointmind * <= 4.1.0