Impact
The vulnerability is a stored Cross‑Site Scripting flaw in the WordPress GetResponse Forms plugin. When an attacker submits malicious input through the form interface, the data is stored and later rendered to visitors without proper neutralization, allowing arbitrary client‑side scripts to execute in the browsers of users who view the affected page.
Affected Systems
The flaw affects fatcatapps GetResponse Forms WordPress plugin versions up to and including 2.6.0. Any WordPress site running those versions and accepting form submissions is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. It is inferred that the attack vector involves an attacker submitting malicious data via the form interface, which is then rendered to all users who view the affected page. Successful exploitation does not appear to require privileged access on the site, so a non‑authenticated attacker could be sufficient to inject the payload.
OpenCVE Enrichment
EUVD