Impact
The flaw is an improper neutralization of user input when generating web pages, enabling reflected cross‑site scripting. An attacker can embed malicious scripts in query parameters or form inputs that are reflected back to the victim's browser, potentially leading to credential theft, session hijacking, or site defacement. The weakness is identified as CWE‑79 and compromises the confidentiality and integrity of data handled by the affected site.
Affected Systems
The vulnerability exists in the cmsMinds Pay with Contact Form 7 plugin, affecting all releases from its earliest version up to and including 1.0.4. WordPress installations using any of these plugin versions are at risk. No specific WordPress core versions are cited, so any WordPress site installing the affected plugin needs remediation.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity. The EPSS score of less than 1% suggests exploitation is unlikely but not impossible, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is reflected; an attacker must lure a user to a crafted URL or form that includes malicious payloads. Successful exploitation requires the victim to load the page; no server‑side state changes occur. Overall risk is moderate but mitigatable through official updates.
OpenCVE Enrichment
EUVD