Impact
Improper neutralization of input during web page generation in the digitaldonkey Multilang Contact Form plugin allows attackers to embed arbitrary scripts that are executed in the browsers of visitors who view the reflected data. The weakness is categorized as CWE‑79 and allows reflected XSS through contaminated user input.
Affected Systems
The affected product is the WordPress plugin ‘Multilang Contact Form’ from digitaldonkey. All versions from the earliest release up to and including 1.5 are impacted; any deployment using 1.5 or older should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker crafting a URL or form input that includes malicious JavaScript; the site must be publicly accessible for the reflected payload to execute in victim browsers. No authentication or privilege escalation is required, allowing any site visitor to potentially trigger the XSS.
OpenCVE Enrichment
EUVD