Impact
The Gravity Forms CSS Themes with Fontawesome and Placeholders plugin fails to sanitize input that is later rendered in a web page, an attacker to store malicious JavaScript. This stored XSS can be executed in the browsers of any user who views a page processed by the plugin, potentially leading to theft of session cookies, defacement, or redirection. The weakness is identified as CWE‑79, improper neutralization of input during web page generation.
Affected Systems
The affected system is the WordPress plugin Gravity Forms CSS Themes with Fontawesome and Placeholders, under the Maros Pristas brand. Versions from the initial release through 8.5 are impacted; any installation using these or earlier releases is vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to inject malicious code into a location that persists and is rendered by the plugin, typically through administrative access to plugin settings or by adding content to a form field that is later outputting unescaped data. Successful exploitation would be client‑side, with impact limited to the victim browsers that load the compromised page.
OpenCVE Enrichment
EUVD