Impact
The Contact Form 7 Star Rating plugin stores user input without proper escaping, enabling an attacker to submit malicious scripts that are later rendered in a page. When a registered or guest user submits a rating, the plugin saves that content. Any visitor viewing pages that include that rating will execute the script in their browser, potentially leading to session hijacking, credential theft, or defacement.
Affected Systems
The vulnerability affects the WordPress plugin Contact Form 7 Star Rating supplied by themelogger, in all releases up to and including version 1.10. Versions newer than 1.10 are presumed secure unless new information emerges. All WordPress sites that have installed the plugin at or below this version are vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. Attackers require the ability to submit a rating via the plugin or otherwise influence the form input; the stored nature of the flaw means that once payload is stored, it will affect all site visitors until the data is removed or the plugin is patched.
OpenCVE Enrichment
EUVD