Impact
The elfsight Contact Form widget plugin for WordPress allows an unauthenticated attacker to retrieve embedded sensitive data, exposing confidential system information. This data exposure flaw is identified as CWE‑497, meaning the application leaks data that should not be publicly accessible.
Affected Systems
All versions of the elfsight Contact Form widget up to and including 2.3.1 are affected. The vulnerable component is a WordPress plugin installed on a site that hosts contact forms.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability, while an EPSS score of < 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is that any visitor to the website could trigger the plugin’s data retrieval mechanism and obtain sensitive information, without the need for authentication or elevated privileges.
OpenCVE Enrichment
EUVD