CVE-2025-66103: WordPress WPCal.io plugin <= 0.9.5.9 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Revmakx WPCal.Io allows DOM-Based XSS.This issue affects WPCal.Io: from n/a through 0.9.5.9.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in revmakx WPCal.io wpcal allows DOM-Based XSS.This issue affects WPCal.io: from n/a through <= 0.9.5.9.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66103?
CVE-2025-66103 has been classified with a moderate severity level due to its impact on web application security.
How do I fix CVE-2025-66103?
To fix CVE-2025-66103, update Revmakx WPCal.Io to a version higher than 0.9.5.9.
What type of vulnerability is CVE-2025-66103?
CVE-2025-66103 is a Cross-site Scripting (XSS) vulnerability affecting the DOM of the application.
Which versions of WPCal.Io are affected by CVE-2025-66103?
CVE-2025-66103 affects all versions of WPCal.Io from n/a up to and including version 0.9.5.9.
What are the consequences of CVE-2025-66103 being exploited?
Exploitation of CVE-2025-66103 may allow attackers to execute arbitrary JavaScript in the context of the affected web application.