Impact
Improper neutralization of user input during web page generation in the iContact for Gravity Forms WordPress plugin results in a reflected XSS vulnerability. This flaw permits an attacker to inject arbitrary JavaScript that is echoed back in the page response. When a victim clicks a crafted link or submits a specially crafted value, the malicious script runs in the victim’s browser, potentially stealing session cookies, defacing content, or facilitating further attacks.
Affected Systems
WordPress sites that have the Zack Katz iContact for Gravity Forms plugin installed, with affected versions ranging from the earliest release through version 1.3.2.
Risk and Exploitability
The CVSS score of 7.1 reflects a high severity impact, while an EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to exploit this flaw by delivering a malicious link or form input to unsuspecting users, causing the injected script to execute in their browsers. The risk is elevated due to the wide deployment of WordPress, but the low likelihood suggests mitigation is still advisable.
OpenCVE Enrichment