Impact
The vulnerability stems from improper neutralization of user-supplied input during web page generation in PluginsCafe’s Range Slider Addon for Gravity Forms. An attacker can inject arbitrary script payloads that are reflected in the browser’s response, enabling classic Reflected Cross‑Site Scripting attacks. A successful exploitation would allow attackers to hijack user sessions, deface pages, or perform other malicious actions in the context of the authenticated user.
Affected Systems
WordPress sites that have installed the Range Slider Addon for Gravity Forms from PluginsCafe, versions from the earliest available through 1.1.6 inclusive. The vulnerability affects the plugin itself and any WordPress installation that hosts the forms powered by it.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating a high severity level, and an EPSS score of less than 1%, suggesting a very low probability of being actively exploited at this time. It is not listed in the CISA KEV catalogue. The likely attack vector is through crafted URLs or form submissions that include malicious script fragments; the attacker needs only to entice a user to load a page or submit a form that triggers the reflected payload.
OpenCVE Enrichment