Impact
Improper neutralization of input in the Easy Contact Form Lite plugin allows attackers to embed malicious JavaScript that is stored and later rendered to users. This Stored XSS flaw, classified as CWE‑79, can lead to defacement, credential theft, or other client‑side compromise when other visitors view the vulnerable page.
Affected Systems
WordPress sites running GhozyLab Easy Contact Form Lite plugin version 1.1.25 or earlier are affected. The vulnerability applies to all releases from the original version up to and including 1.1.25.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, while an EPSS score of less than 1 % shows a low probability of exploitation in the current environment. The flaw is not listed in CISA's KEV catalog. Attackers can exploit it by injecting crafted input through the contact form, which is then persisted and served to site visitors, leading to script execution in their browsers.
OpenCVE Enrichment
EUVD