Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imithemes Eventer eventer allows Reflected XSS.This issue affects Eventer: from n/a through < 3.9.9.
Security readout for executives and security teams
Plain-English summary
CVE-2025-22635 is a reflected cross-site scripting issue in the WordPress Eventer booking plugin before version 3.9.9. Affected public WordPress sites could expose visitors or administrators to script execution after user interaction. Sources do not state active exploitation.
Executive priority
Treat as a high-priority WordPress plugin update for internet-facing sites. It is not confirmed as actively exploited in the provided sources, but no-login reflected XSS can still create business risk through targeted users and brand-facing pages.
Technical view
The CVE describes CWE-79 improper input neutralization during web page generation in imithemes Eventer. It is rated CVSS 3.1 7.1 high: network reachable, low complexity, no privileges required, user interaction required, changed scope, and low confidentiality, integrity, and availability impact.
Likely exposure
Exposure is limited to WordPress installations using the Eventer plugin below 3.9.9. Public-facing event or booking pages increase practical risk, especially where administrators use the same browser session to manage WordPress.
Exploitation context
The source bundle does not include exploit code, exploitation reports, or CISA KEV listing. Risk depends on whether attackers can cause a targeted user to interact with attacker-controlled content that reaches the vulnerable page generation path.
Researcher notes
The provided evidence identifies the affected range and CVSS vector but does not include vulnerable parameters, proof of concept, or exploit telemetry. Avoid assuming broader Eventer or WordPress impact beyond plugin versions before 3.9.9.
Mitigation direction
Inventory WordPress sites for the Eventer plugin and installed version.
Update Eventer to version 3.9.9 or later where available.
If immediate update is unavailable, review vendor guidance and reduce plugin exposure.
Apply normal WordPress hardening, including least-privilege admin accounts.
Monitor web and WordPress logs for suspicious reflected XSS probes.
Validation and detection
Confirm whether Eventer is installed on each WordPress site.
Verify all Eventer installations are version 3.9.9 or later.
Review public event and booking routes for exposure.
Check security monitoring for XSS-related alerts or unusual requests.
Document any sites requiring vendor guidance or compensating controls.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.