Impact
The affected plugin contains a Cross-Site Request Forgery flaw that can lead to stored cross‑site scripting. An attacker who can exploit the CSRF weakness may inject malicious code into the application, potentially allowing them to deface the site, steal user data, or perform further attacks against site visitors.
Affected Systems
The plugin W3SCloud Contact Form 7 to Zoho CRM from W3S Cloud Technology is vulnerable in all versions up to and including 3.2. No specific patch version is listed; the issue covers the entire range from the initial release to 3.2.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity vulnerability. The EPSS score is below 1 %, meaning exploitation is considered unlikely with current data. The vulnerability is not yet listed in the CISA KEV catalog. Attackers would need to convince a logged‑in user or administrator to visit a specially crafted URL or click a malicious link to trigger the CSRF, after which the stored XSS payload could be executed in their browser.
OpenCVE Enrichment
EUVD