Impact
The vulnerability originates from improper neutralization of user input during web page generation in the ANON::form embedded secure form plugin, enabling DOM‑based cross‑site scripting. A crafted payload can be reflected into the client browser and executed as JavaScript, allowing an attacker to manipulate page content or run arbitrary code within the victim’s browser context.
Affected Systems
This flaw affects the WordPress plugin ANON::form embedded secure form from its first release through version 1.7 inclusive. Consequently, any WordPress site that has the plugin at version 1.7 or earlier is susceptible to the vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests that exploitation may not be widespread yet, and the CVE is not listed in CISA KEV. The attack vector is client side; an attacker must deliver a crafted form to a user’s browser, which then triggers the JavaScript injection. The risk is therefore moderate but limited to clients that load the vulnerable form.
OpenCVE Enrichment
EUVD