Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anildhiman MJ Contact us mj-contact-us allows Reflected XSS.This issue affects MJ Contact us: from n/a through <= 5.2.3.
Published: 2025-01-24
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, enabling reflected cross-site scripting within the MJ Contact us plugin. If an attacker crafts a URL that includes malicious script content, that script executes in the victim’s browser when the link is visited, potentially hijacking sessions, stealing cookies or defacing the site. The flaw is documented as CWE-79 and does not provide remote code execution on the server, but it does compromise the integrity and confidentiality of a user’s session data.

Affected Systems

The affected product is the MJ Contact us WordPress plugin developed by anildhiman. Versions from the beginning of its release timeline up to and including 5.2.3 are impacted. Users should verify their installed version and plan for remediation if it falls within this range.

Risk and Exploitability

The CVSS score is 7.1, indicating high severity for an XSS flaw. The EPSS score is less than 1%, suggesting a low probability of widespread exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a user clicking a maliciously crafted link or visiting a specially crafted URL, after which the attacker’s script runs in the victim’s browser context. While exploitation requires user interaction, the impact on user sessions can be significant if the attacker succeeds.

Generated by OpenCVE AI on May 2, 2026 at 05:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the MJ Contact us plugin to version 5.2.4 or later when it becomes available to apply the vendor’s fix for the input sanitization flaw.
  • If an immediate upgrade is not possible, remove or disable any page that displays user‐supplied query data from the contact form to eliminate the attack surface.
  • Configure a Web Application Firewall or server‑side filtering rules that strip or escape characters that could form script tags from URL parameters before they reach the plugin.

Generated by OpenCVE AI on May 2, 2026 at 05:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3503 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound MJ Contact us allows Reflected XSS. This issue affects MJ Contact us: from n/a through 5.2.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound MJ Contact us allows Reflected XSS. This issue affects MJ Contact us: from n/a through 5.2.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in anildhiman MJ Contact us mj-contact-us allows Reflected XSS.This issue affects MJ Contact us: from n/a through <= 5.2.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 27 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 11:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound MJ Contact us allows Reflected XSS. This issue affects MJ Contact us: from n/a through 5.2.3.
Title WordPress MJ Contact us Plugin <= 5.2.3 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:23.398Z

Reserved: 2025-01-16T11:31:35.915Z

Link: CVE-2025-23885

cve-icon Vulnrichment

Updated: 2025-01-24T14:08:04.310Z

cve-icon NVD

Status : Deferred

Published: 2025-01-24T11:15:11.660

Modified: 2026-06-17T08:57:40.487

Link: CVE-2025-23885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:45:20Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')