Impact
The vulnerability is an improper neutralization of user‑supplied input during web page generation, allowing malicious JavaScript to be reflected back in the HTTP response. This reflected XSS could be executed in the browser of any user who loads the affected page, potentially enabling client‑side attacks. The weakness is identified as CWE‑79 and is limited to the Daman Jeet Real Time Validation for Gravity Forms plugin.
Affected Systems
The flaw affects installations of the Daman Jeet Real Time Validation for Gravity Forms plugin on WordPress sites running any version from the initial release up to and including version 1.7.0. All sites that have the plugin installed within this version range are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity impact. The EPSS score of less than 1% suggests a low probability of exploitation at present, yet the vulnerability remains significant for high‑traffic sites because no authentication or privileged access is required. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via a crafted query string or form input that contains malicious script, which is then reflected back to the victim. No special privileges are required to exploit.
OpenCVE Enrichment
EUVD