Impact
The Cf7Save Extension plugin for WordPress includes an improper neutralization of input during web page generation, allowing attackers to inject malicious scripts when certain input fields are reflected back to the user. This reflected cross‑site scripting flaw can enable session hijacking, data theft, defacement, or the execution of arbitrary code in the victim's browser. The vulnerability is catalogued as CWE‑79.
Affected Systems
Sites running WordPress with Cf7Save Extension version 1 or earlier are impacted. The plugin is vulnerable when it processes user-supplied data that is subsequently displayed unfiltered in the plugin’s output.
Risk and Exploitability
The CVSS base score of 7.1 indicates high severity, while the EPSS score of less than 1 percent suggests a low exploitation probability in the wild. The vulnerability is not listed in the CISA KEV catalog, yet its potential impact warrants high patching priority. Attackers could exploit the flaw by sending crafted HTTP requests to the form pages that incorporate the vulnerable plugin, making any site receiving untrusted input through this plugin especially at risk.
OpenCVE Enrichment
EUVD