CVE-2025-14548 describes a Stored Cross-Site Scripting (XSS) vulnerability in the WordPress Calendar plugin, affecting all versions up to and including 1.3.16. Authenticated attackers with Contributor-level access or higher can inject malicious web scripts into the 'event_desc' parameter, which execute when a user views an affected page, provided an administrator has configured the plugin to allow lower privilege users to manage events. The vulnerability carries a CVSS score of 6.4 (Medium), indicating a low attack complexity and requiring low privileges, but with a change in scope. Successful exploitation could lead to limited confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The CVE has received minimal community discussion and media coverage, suggesting a low level of public awareness or immediate concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.3.16CPE match | cpe:2.3:a:kieranoshea:calendar:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.