Impact
The Contact Us Simple Form plugin for WordPress allows authenticated users who have administrator-level permissions to inject arbitrary scripts through the plugin’s settings page. The vulnerability arises from insufficient input sanitization and output escaping of user‑supplied attributes, resulting in a stored XSS flaw that will execute when any user visits a page containing the injected data. This flaw permits malicious code to run in the context of the site’s pages, potentially allowing attackers to modify page content or conduct further attacks while a legitimate user is browsing.
Affected Systems
WordPress sites that have the Contact Us Simple Form plugin installed from the bruterdregz developer, in any version up to and including 1.0. All installations of versions 1.0 or earlier without an applied patch are susceptible.
Risk and Exploitability
The CVSS score of 4.4 classifies the issue as moderate severity, while the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, suggesting no known exploited instances. Attackers must be authenticated with administrator privileges to exploit the vulnerability, meaning the risk is primarily for internal threat actors or compromised admin accounts.
OpenCVE Enrichment