Impact
This vulnerability is caused by improper neutralization of user input when generating a web page, resulting in reflected XSS. An attacker can inject malicious scripts that will execute in the browser of any user who interacts with the vulnerable form or URL. The primary impact is client‑side code execution, which can lead to defacement, theft of cookies and session tokens, and the execution of additional malicious actions on behalf of the victim.
Affected Systems
The issue affects the WordPress plugin Contact Form 7 – Paystack Add‑on, developed by crystalwebpro, with all releases up to and including version 1.2.3.
Risk and Exploitability
With a CVSS score of 7.1, this represents a high severity vulnerability. The EPSS score of less than 1% indicates that widespread exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers could exploit it by embedding malicious payloads in seemingly legitimate query parameters or form fields that are reflected back to the user. Successful exploitation would give the attacker client‑side control over the victim’s browser, potentially allowing credential theft, session hijacking, or further compromise of the site.
OpenCVE Enrichment
EUVD