Stored Cross-Site Scripting Vulnerability in Appointmind Plugin by WordPress
CVE-2025-9851
What is CVE-2025-9851?
The Appointmind plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability via its 'appointmind_calendar' shortcode. This flaw, present in all versions up to and including 4.1.0, results from inadequate input sanitization and output escaping on attributes provided by users. As a consequence, authenticated users with contributor-level access and higher are able to inject malicious scripts into pages. These scripts can be executed in the browser of any user who accesses the compromised pages, posing a significant security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Appointmind * <= 4.1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved