Impact
The vulnerability is an improper neutralization of input during web page generation that allows attackers to store malicious JavaScript in the Piotnet Forms plugin. Once injected, the code executes in the browsers of visitors who view the affected form page, potentially enabling session hijacking, cookie theft, or defacement of the site. The flaw is a classic Cross‑Site Scripting flaw (CWE‑79).
Affected Systems
WordPress sites using the Piotnet Forms plugin from any version up to and including 1.0.30 are affected; later versions contain a fix.
Risk and Exploitability
The CVSS score of 5.9 reflects a moderate impact when the attack succeeds. The EPSS score of less than 1 % suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector, inferred from the description of stored XSS, involves posting malicious payloads through free‑form fields in the plugin’s forms and then tricking or enticing users to visit the pages that render the stored data.
OpenCVE Enrichment
EUVD