Impact
The vulnerability is an improper neutralization of input during web page generation, leading to a stored cross‑site scripting flaw in the Piotnet Forms plugin. When a malicious script is entered into a form field, the plugin saves the data and later serves it to other users without proper escaping. This flaw is identified as CWE‑79. Successful exploitation would allow an attacker to run arbitrary JavaScript in the victim’s browser, potentially causing session hijacking, credential theft, or defacement.
Affected Systems
All installations of the Piotnet Forms plugin for WordPress with a version number of 1.0.30 or earlier are affected. No other versions are currently known to be vulnerable.
Risk and Exploitability
The CVSS base score of 5.9 indicates moderate severity for a stored XSS flaw, while the EPSS score of less than 1% shows a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a submitted form entry that an attacker can manipulate; this inference is drawn because the flawed sandboxing occurs when form data is stored and later displayed to site visitors.
OpenCVE Enrichment
EUVD