Impact
An attacker can exploit an improper neutralization of user‑supplied input when the Spark GF Failed Submissions plugin renders page content, enabling reflected XSS. The vulnerability is limited to the plugin’s output generation and does not require elevated privileges or authentication. Successful exploitation allows injection of arbitrary HTML or JavaScript into the victim’s browser, potentially leading to session theft, credential compromise, or defacement of the site’s appearance.
Affected Systems
The affected product is the Mark Parnell Spark GF Failed Submissions WordPress plugin. Versions from the initial release through version 1.3.5 are vulnerable. Any WordPress site that currently runs a 1.3.5 or earlier instance of this plugin is at risk.
Risk and Exploitability
The CVSS score of 7.1 places this issue in the High category. Its EPSS score of less than 1% indicates that, while the vulnerability exists, it is unlikely to be widely exploited at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be reflected (web‑based), suggesting that a crafted URL or form submission could trigger the malicious payload when a user views the affected page. Overall, the risk is moderate but not negligible, and prompt remediation is advisable.
OpenCVE Enrichment
EUVD