Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in animexxx dForms dforms allows Reflected XSS.This issue affects dForms: from n/a through <= 1.0.
Published: 2025-01-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The dForms plugin for WordPress contains an Improper Neutralization of Input During Web Page Generation vulnerability that permits reflected Cross‑Site Scripting. An attacker can inject malicious JavaScript into the list form view that will be executed in the victim’s browser when the crafted URL is loaded. The impact is that an attacker can hijack sessions, exfiltrate cookies, deface content, or drive phishing activity. The weakness is a classic input validation flaw, categorized as CWE‑79.

Affected Systems

This issue affects the animexxx dForms WordPress plugin version 1.0 and all earlier releases. Any WordPress site that has installed this plugin and has not upgraded past 1.0 is potentially vulnerable. Vulnerable installations must be identified and assessed for removal or upgrade.

Risk and Exploitability

The advisory lists a CVSS score of 7.1, indicating a high severity rating, while the EPSS score is below 1%, suggesting that current exploitation likelihood is low but not zero. The vulnerability is not yet catalogued in CISA's Known Exploited Vulnerabilities database. Based on the nature of reflected XSS, the attack vector is most likely a user‑directed request that includes malicious query or form data; authentication is not required, so exposure depends on how many visitors are exposed to the vulnerable view.

Generated by OpenCVE AI on May 1, 2026 at 19:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the dForms plugin to the latest version available (any release newer than 1.0).
  • If an update is not yet available, temporarily disable or uninstall the dForms plugin from your WordPress installation.
  • Ensure that any remaining user input displayed by the plugin is output‑escaped using WordPress functions such as esc_html() or esc_url().

Generated by OpenCVE AI on May 1, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3269 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound dForms allows Reflected XSS. This issue affects dForms: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound dForms allows Reflected XSS. This issue affects dForms: from n/a through 1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in animexxx dForms dforms allows Reflected XSS.This issue affects dForms: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 22 Jan 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound dForms allows Reflected XSS. This issue affects dForms: from n/a through 1.0.
Title WordPress dForms plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:05:08.690Z

Reserved: 2025-01-16T11:26:45.456Z

Link: CVE-2025-23592

cve-icon Vulnrichment

Updated: 2025-01-22T16:17:07.795Z

cve-icon NVD

Status : Deferred

Published: 2025-01-22T15:15:18.097

Modified: 2026-06-17T08:55:37.860

Link: CVE-2025-23592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T20:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')