Impact
An improper neutralization of user input in the Vikas Ratudi VPSUForm WordPress plugin allows attackers to embed malicious scripts that are returned and executed in a victim’s browser when a crafted URL is visited. The reflected XSS can be used to steal session tokens, deface the page, or execute client‑side attacks, violating confidentiality, integrity, and user trust. The weakness is a classic input validation failure, identified as CWE‑79.
Affected Systems
WordPress sites that have Vikas Ratudi’s VPSUForm v-form plugin, version 3.1.9 or earlier, are affected. No specific WordPress core versions are cited, so any site running a vulnerable plugin instance is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity with moderate to high impact. The EPSS score of less than 1% suggests that exploitation attempts are rare but still possible. The vulnerability is not listed in CISA’s KEV catalog. Attackers must supply a malicious link to a user who then opens it in their browser, which is a user‑interaction‑dependent attack vector. The lack of a publicly documented exploit script and the restricted nature of the bug reduce the likelihood of widespread automated attacks, but businesses should treat the flaw as high risk until patched.
OpenCVE Enrichment
EUVD