Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Jeffrey Contact Form 7 Round Robin Lead Distribution contact-form-7-round-robin-lead-distribution allows Reflected XSS.This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through <= 1.2.1.
Published: 2025-01-22
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an improper neutralization of input during web page generation, allowing an attacker to embed malicious JavaScript code that is reflected back in the response to a victim. When a user views data submitted through the Contact Form 7 Round Robin Lead Distribution plugin, the script runs in the victim’s browser, giving the attacker the ability to steal session cookies, hijack the user’s session, or deface the site. The weakness is identified as CWE‑79.

Affected Systems

WordPress plugin Contact Form 7 Round Robin Lead Distribution by David Jeffrey, any installation of the plugin with a version equal to or lower than 1.2.1.

Risk and Exploitability

The CVSS score of 7.1 indicates a high impact, while the EPSS score of < 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can trigger the XSS by sending a crafted request to the plugin’s endpoint which reflects user input back to the visitor. Because the flaw is reflected XSS, the attacker must control the input that is reflected in the response, typically by manipulating a form or URL that the victim visits. Those who administer the site or can inject content through the plugin may exploit it, and security teams should monitor for suspicious traffic and promptly patch or mitigate the vulnerable code.

Generated by OpenCVE AI on May 1, 2026 at 19:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the plugin to a version newer than 1.2.1 to apply the vendor‑supplied fix.
  • If an immediate upgrade is not possible, disable the plugin or block the forms that use the vulnerable functionality to prevent exploitation.
  • Ensure that any user‑supplied data displayed by the plugin is properly escaped or sanitized using WordPress’s built‑in functions to mitigate XSS risk.

Generated by OpenCVE AI on May 1, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3444 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Contact Form 7 Round Robin Lead Distribution allows Reflected XSS. This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through 1.2.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Contact Form 7 Round Robin Lead Distribution allows Reflected XSS. This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through 1.2.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Jeffrey Contact Form 7 Round Robin Lead Distribution contact-form-7-round-robin-lead-distribution allows Reflected XSS.This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through <= 1.2.1.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 22 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Contact Form 7 Round Robin Lead Distribution allows Reflected XSS. This issue affects Contact Form 7 Round Robin Lead Distribution: from n/a through 1.2.1.
Title WordPress Contact Form 7 Round Robin Lead Distribution Plugin <= 1.2.1 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:20.864Z

Reserved: 2025-01-16T11:30:44.310Z

Link: CVE-2025-23812

cve-icon Vulnrichment

Updated: 2025-01-22T15:09:04.827Z

cve-icon NVD

Status : Deferred

Published: 2025-01-22T15:15:24.437

Modified: 2026-04-23T15:24:33.620

Link: CVE-2025-23812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T19:30:23Z

Weaknesses