Impact
The vulnerability arises because user‑supplied data is rendered without proper neutralization, enabling attackers to inject JavaScript that executes in the victim’s browser. This flaw can result in session hijacking, credential theft, or website defacement, compromising the confidentiality and integrity of user sessions. The weakness is classified as CWE‑79 – Improper Neutralization of Input During Web Page Generation.
Affected Systems
The flaw impacts the Breezing Forms plugin from Crosstec for WordPress, affecting all releases up to and including version 1.2.8.11. Any installation of the plugin within this version range is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of < 1% points to a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to craft a malicious URL containing a payload and persuade a legitimate user to visit it, making the attack vector web‑based and user‑initiated.
OpenCVE Enrichment
EUVD