Impact
Improper neutralization of input in the Contact Form vCard Generator plugin allows malicious script to be stored and executed in browsers that view the affected page, enabling an attacker to run code in the visitor’s context. This can lead to theft of session data or manipulation of page content.
Affected Systems
Any WordPress site that installed the Contact Form vCard Generator plugin by Ashish Ajani in versions up to and including 2.4 is affected. Sites using earlier releases are also impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by submitting malicious input through the plugin’s contact form, which is stored and later rendered in a page viewed by other users, triggering the injected script in their browsers.
OpenCVE Enrichment
EUVD