Impact
The plugin contains an improper neutralization of input during web page generation that allows attackers to inject arbitrary scripts. This reflected XSS flaw is triggered when a user submits form data that is rendered back to the browser without escaping, enabling the execution of malicious code in the visitor’s context, which can lead to cookie theft, defacement, or other malicious actions.
Affected Systems
The vulnerability affects WordPress sites that use the Rebrand Fluent Forms plugin version 1.0 or earlier, released by rebrandpress.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score is below 1%, implying a low current exploitation likelihood. The flaw is not listed in CISA’s KEV catalog. Exploitation typically requires crafting a malicious input in the form field that is reflected in the page, allowing script execution when the victim views the result. Immediate patching or removal of the plugin is the recommended mitigation.
OpenCVE Enrichment
EUVD