CVE-2025-39372
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elbisnero WordPress Events Calendar Registration & Tickets wpeventplus allows Reflected XSS.This issue affects WordPress Events Calendar Registration & Tickets: from n/a through <= 2.6.0.
CWE
- CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Affected
- elbisnero / WordPress Events Calendar Registration & Tickets — v=0 ≤2.6.0 [affected]
CVSS
- (none)
References
Source
cvelistV5-main/cves/2025/39xxx/CVE-2025-39372.json