Impact
The issue is a stored XSS flaw in the QuantumCloud Conversational Forms for ChatBot plugin caused by improper neutralization of user input during web page generation. Injected JavaScript can run in the browsers of any visitor to the affected pages. This falls under CWE‑79.
Affected Systems
The vulnerable component is the QuantumCloud Conversational Forms for ChatBot WordPress plugin. All releases up to and including version 1.4.2 are affected. No patch version is listed in the data.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate‑to‑high severity, while the EPSS score of less than 1% points to low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is user‑submitted form data stored by the plugin, as the vulnerability arises from improper neutralization of input during web page generation, which is inferred from the description. Successful exploitation could allow client‑side script execution that may enable theft of information or other client‑side attacks, though specific impacts are not detailed in the CVE data.
OpenCVE Enrichment
EUVD