Impact
The vulnerability is a reflected XSS flaw that allows attackers to inject malicious scripts into the web page served by the Customizable Captcha and Contact Us plugin. A successful exploitation could lead to data theft, session hijacking, or defacement in the victim’s browser. The weakness is identified as CWE–79, improper neutralization of input during web page generation.
Affected Systems
The affected product is the Customizable Captcha and Contact Us plugin for WordPress, version 1.0.2 and earlier. No start version is specified, so any deployment of the plugin with a revision number <= 1.0.2 should be considered vulnerable.
Risk and Exploitability
The CVSS base score is 7.1, indicating a medium to high severity. The EPSS score of less than 1% suggests the probability of exploitation is low at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely exploit the plugin’s form input fields to deliver malicious payloads to users who view the resulting page.
OpenCVE Enrichment
EUVD