Impact
The Beauty Contact Popup Form plugin contains a stored Cross‑Site Scripting vulnerability that allows an attacker to inject malicious script into the form and have it executed whenever a visitor loads the page. This flaw is a classic Client‑Side Injection (CWE‑79) that does not grant direct code execution on the server but enables attackers to hijack user sessions, deface the site, or redirect users to phishing pages. The vulnerability is triggered by improperly neutralized user input stored in the form’s configuration or content.
Affected Systems
WordPress sites running Dilip Kumar’s Beauty Contact Popup Form plugin version 6.0 or earlier are affected. Administrator or author permissions that allow editing the form can create or modify content that leads to script injection.
Risk and Exploitability
The vulnerability scores a moderate CVSS 5.9, and its EPSS score of less than 1% indicates a very low current exploitation probability. It is not listed in the CISA KEV catalog. Attackers would need web access to the site’s administration area to craft malicious input, and the impact is limited to users who view the affected form. Despite the low likelihood, the potential for client‑side code execution warrants prompt remediation.
OpenCVE Enrichment
EUVD