A vulnerability, which was classified as problematic, has been found in Appointmind Plugin up to 4.1.0 on WordPress. Affected by this vulnerability is the function
appointmind_calendar
of the component Shortcode Handler. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2025-9851. The attack is possible to be carried out remotely. No exploit exists.