Impact
The WordPress plugin Contact Us By Lord Linus, developed by Rohitashv Singhal, contains an improper neutralization of input during page generation that allows reflected cross-site scripting. An attacker can embed malicious JavaScript in a URL or form field that is subsequently reflected in the plugin's output without adequate sanitization. This flaw permits execution of arbitrary code in the context of a victim's browser, enabling phishing, session hijacking, or defacement.
Affected Systems
All installations of the WordPress plugin Contact Us By Lord Linus, version 2.6 or earlier, are affected. No other vendors or product versions are listed, so any site using these plugin versions remains vulnerable.
Risk and Exploitability
The CVSS score of 7.1 signals a high severity risk that can compromise confidentiality, integrity, or availability if a victim visits a crafted link containing malicious payloads. The EPSS score of less than 1 % indicates a low probability of active exploitation, but the vulnerability remains present and is not listed in CISA's KEV catalog. The likely attack vector is a reflected XSS payload delivered via a malicious URL or form input that a user is lured to click, and the issue originates from insufficient input validation.
OpenCVE Enrichment
EUVD