CVE-2025-49398: WordPress Easy Appointments plugin <= 3.12.14 - Content Injection vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Easy Appointments Easy Appointments easy-appointments allows Code Injection.This issue affects Easy Appointments: from n/a through <= 3.12.14.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49398?
CVE-2025-49398 is considered a high severity vulnerability due to its potential for code injection through improper handling of HTML tags.
How do I fix CVE-2025-49398?
To fix CVE-2025-49398, update Easy Appointments to version 3.12.15 or later, as this version addresses the vulnerability.
What types of attacks can CVE-2025-49398 facilitate?
CVE-2025-49398 can facilitate cross-site scripting (XSS) attacks, allowing malicious scripts to be injected into web pages.
Which versions of Easy Appointments are affected by CVE-2025-49398?
CVE-2025-49398 affects Easy Appointments versions up to and including 3.12.14.
Is user input a factor in CVE-2025-49398?
Yes, CVE-2025-49398 stems from improper neutralization of user input, allowing script injection through unvalidated HTML tags.