CyberRota Analysis
AI-GeneratedThe Spiffy Plugin for WordPress versions prior to 5.0.9 is vulnerable to Stored Cross-Site Scripting (XSS) in the Event Title field, allowing authenticated attackers with contributor-level access to inject malicious scripts. This could enable them to redirect users to malicious sites or gain control over user accounts. WordPress site administrators and users of the Spiffy Plugin should prioritize updating to the latest version to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) can exploit this to redirect user to malicious site or control the account.