Impact
The vulnerability in the FormGent WordPress plugin allows attackers to store malicious scripts in form submission fields. Once stored, the scripts execute in the browsers of any user who views the affected page, enabling defacement, cookie theft, or malicious redirects. The weakness stems from insufficient input sanitization and output escaping, classified as CWE‑79.
Affected Systems
Any WordPress site that has the FormGent – Next‑Gen AI Form Builder installed versions up to and including 1.9.2. The plugin is distributed by wpwax and is widely used for multi‑step forms, quizzes, and payment processing. Sites using earlier versions are also vulnerable until they upgrade.
Risk and Exploitability
The CVSS score of 7.2 indicates a high-severity flaw that is exploitable by unauthenticated actors. No EPSS score is listed, and the vulnerability is not part of the CISA KEV catalog, but the attack vector is the web interface, allowing an attacker to submit a crafted form without credentials. Once the payload is stored, any user visiting the page is impacted, giving potential attackers the ability to hijack sessions or deface content. Vigilance is required to detect and mitigate the stored code before it reaches users.
OpenCVE Enrichment