CVE-2025-11995: Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting
The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11995?
The severity of CVE-2025-11995 is considered medium due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2025-11995?
To fix CVE-2025-11995, update the Community Events plugin to version 1.5.3 or later, which includes the necessary input sanitization and output escaping.
Who is impacted by CVE-2025-11995?
All users of the Community Events plugin for WordPress versions up to and including 1.5.2 are impacted by CVE-2025-11995.
What types of attacks can CVE-2025-11995 enable?
CVE-2025-11995 can enable unauthenticated attackers to inject malicious scripts into event details, leading to stored cross-site scripting attacks.
Is CVE-2025-11995 simple to exploit?
Yes, CVE-2025-11995 can be exploited easily by unauthenticated attackers due to the insufficient input sanitization of the event details parameter.