Impact
The vulnerability is a DOM–based cross‑site scripting flaw in the WordPress CF7 Auto Responder Addon. Input that is not properly neutralized can be inserted into a page, allowing an attacker to execute arbitrary JavaScript in the victim’s browser, potentially stealing session data, hijacking the user, or performing actions on the user’s behalf, which compromises the confidentiality, integrity, and availability of the web application.
Affected Systems
The affected product is the CF7 Auto Responder Addon plugin developed by kamleshyadav, versions from the initial release through 2.4 inclusive.
Risk and Exploitability
The CVSS base score of 7.1 signals a high severity flaw. Because the EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, the likelihood of exploitation appears low at present. However, the attack vector is client‑side: an attacker must obtain a victim’s browser to view a page that processes the unchecked input, which is feasible for phishing or social engineering campaigns. Admins should assess the exposure and promptly apply the patch.
OpenCVE Enrichment