Impact
The Smart Forms plugin for WordPress allows a user with administrator level access or higher to inject arbitrary JavaScript into the plugin’s admin settings. Because the input is insufficiently sanitized and not properly escaped, the data is stored in the database and later rendered on pages accessed by any user of the site. This Stored XSS flaw (CWE‑79) can be used to execute scripts in visitors’ browsers, potentially leading to session hijacking, data theft, or site defacement.
Affected Systems
WordPress installations running Smart Forms up to and including version 2.6.98 are affected. The vulnerability applies only to multisite WordPress environments and to sites where the unfiltered_html capability has been disabled. The plugin is distributed by the vendor edgarrojas under the name "Smart Forms – when you need more than just a contact form." All other versions are assumed unaffected.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate severity. The EPSS score of less than 1% reflects a very low probability of exploitation as of the latest data. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker already possess administrator-level credentials or succeed in obtaining them; therefore, the risk is primarily among sites with weak access controls or compromised admin accounts.
OpenCVE Enrichment
EUVD