Impact
The vulnerability is an improper neutralization of input during web page generation (Reflected XSS). When untrusted input is reflected back to the page without proper escaping, an attacker can embed malicious JavaScript that runs in the victim’s browser. This can lead to data theft, session hijacking, or defacement of the site. The CVSS score of 7.1 indicates a moderate‑to‑high severity for this type of flaw.
Affected Systems
Vendor Alvind’s Billplz Addon for Contact Form 7 plugin for WordPress is affected. All releases from the first version up to and including 1.2.0 are vulnerable. Users who still run a version ≤ 1.2.0 should assess whether the add‑on is in active use.
Risk and Exploitability
The EPSS score of < 1 % points to a very low probability that the flaw will be actively exploited. The flaw is not listed in the CISA KEV catalog. Exploitation requires that the attacker be able to inject a crafted payload into a form that the plugin renders back to the user, so the attack vector is a web‑based input field that is reflected in the plugin’s output. Because the payload is executed client‑side, the impact is limited to the victim’s browser session and the information that the victim’s browser can access.
OpenCVE Enrichment
EUVD