CVE-2025-24585: WordPress Event post plugin <= 5.9.7 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post event-post allows Stored XSS.This issue affects Event post: from n/a through <= 5.9.7.
Security readout for executives and security teams
Plain-English summary
CVE-2025-24585 is a stored cross-site scripting issue in the WordPress Event post plugin up to 5.9.7. A user with low privileges may be able to save unsafe content that later runs in another user's browser. This can expose data or alter actions within the victim's WordPress session.
Executive priority
Treat this as a near-term WordPress hygiene issue, not an emergency based on the provided evidence. Prioritize internet-facing sites, sites with many contributors, and sites where WordPress administrators regularly view user-submitted event content.
Technical view
The issue is CWE-79 improper neutralization during web page generation in Bastien Ho Event post. CVSS 3.1 is 6.5 with network access, low complexity, low privileges, required user interaction, and changed scope. The bundle identifies affected versions through 5.9.7 but does not name a fixed release.
Likely exposure
Exposure is limited to WordPress sites running the Event post plugin at version 5.9.7 or earlier. Risk is higher where untrusted or low-privileged users can create or edit event-related content that administrators or visitors later view.
Exploitation context
The source bundle does not show CISA KEV listing or active exploitation evidence. The CVSS vector indicates exploitation requires an authenticated low-privileged actor and user interaction. Stored XSS can still be business-relevant because execution may occur later in a more trusted user's browser.
Researcher notes
Do not assume exploit activity or a patch from this bundle alone. The key unknown is whether a fixed version exists. Validate exposure by plugin presence and version, then track vendor or Patchstack guidance. Avoid destructive testing on production WordPress sites.
Mitigation direction
Inventory WordPress sites for Event post / event-post plugin versions 5.9.7 or earlier.
Check vendor, WordPress.org, and Patchstack guidance for a fixed version or workaround.
Update to a vendor-confirmed fixed release when available.
Disable or remove the plugin where business need is low.
Limit plugin publishing and administration rights to trusted users.
Validation and detection
Confirm whether each WordPress site has the Event post plugin installed.
Record installed plugin versions and flag 5.9.7 or earlier.
Review event content workflows for low-privileged or untrusted authors.
Inspect stored event content for unexpected script-like markup.
Verify remediation after update, disablement, or removal.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.