CVE-2025-5258
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The Conference Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<p>Conference Scheduler allows you to easily manage and display complex workshop schedules for conferences and similar events, and also provide information about the workshops on your website in a clean, searchable, responsive interface. Create and manage details about your workshops using the standard WordPress admin interface and display it all on any page of your site with a simple shortcode.</p>
<h4>Features</h4>
<ul>
<li>Add and edit workshops in the standard WordPress admin</li>
<li>Collects and displays important information about each workshop: workshop code, time, location, description, presenter, presenter bio, participant limit</li>
<li>Add files to workshops – lets you easily distribute presentation files or other reference material</li>
<li>Handles parallel sessions</li>
<li>Optionally group workshops by location within a session</li>
<li>Categorize workshops into streams and areas with tags</li>
<li>Search and filter workshop listings on the front-end for easy access</li>
<li>Pick workshops on the front-end so delegates can build their ideal conference schedule</li>
<li>Customize the style of workshops easily using the WordPress customizer</li>
<li>Responsive design means your schedule looks and works great on all devices – delegates can quickly pull out their phone at any time to check the schedule or workshop info</li>
<li>Upgrade to <a href="https://conferencescheduler.com/pro/" rel="nofollow ugc">Conference Scheduler Pro</a> and you also get:
<ul>
<li>Import/Export to/from Excel</li>
<li>Complete user registration system with optional waitlists for space limited workshops</li>
<li>Multi-lingual support with WPML and Polylang compatibility</li>
<li>Extensible architecture for customization – adding fields, display templates, search customization</li>
</ul>
</li>
</ul>
<h3>Feature Requests</h3>
<p>If there is a particular feature that you’d like to see in Conference Scheduler, let me know and I’ll consider adding it.</p>