Impact
The Form To JSON plugin fails to neutralize input properly, allowing an attacker to embed malicious scripts that are executed in the browsers of users who view the generated page, resulting in potential theft of session data or other client‑side data. The flaw is a classic reflected XSS, identified as CWE‑79, and can be triggered by specially crafted query or form parameters.
Affected Systems
All installations of the webgdawg Form To JSON plugin not newer than version 1.0 are impacted. Administrators should verify the plugin version they are running and note that any deployment of 1.0 or earlier is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity with local impact, and the EPSS score of less than 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors include manipulating form or URL parameters that are later reflected in the JSON‑formatted output presented to users.
OpenCVE Enrichment
EUVD