Impact
The vulnerability in the Subscription Form for Feedblitz plugin allows stored XSS due to improper neutralization of user input (CWE-79). A malicious actor can embed JavaScript that will execute in the browsers of any user who views the affected page.
Affected Systems
Affected is the WordPress plugin Subscription Form for Feedblitz developed by Arni Cinco, version 1.0.9 and earlier. WordPress sites that have included this plugin without applying the latest fix are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score is less than 1%, suggesting few exploitation attempts known, and the vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is through the plugin's form interface, requiring an attacker to submit crafted data that is stored and later rendered to visitors, so general web input handling is required.
OpenCVE Enrichment
EUVD