Impact
Inboxify Sign Up Form plugin contains a stored XSS vulnerability caused by insufficient input sanitization. An attacker can submit specially crafted data through the sign‑up form and have that data rendered unsanitized in future page views, allowing the execution of arbitrary JavaScript in the context of the plugin and potentially affecting the confidentiality of user session data or enabling malicious redirects.
Affected Systems
Inboxify: Inboxify Sign Up Form, versions through and including 1.0.4. Any WordPress site that has this plugin installed risks the flaw.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not currently listed in CISA’s KEV catalog. Exploitation would occur via the public sign‑up form, requiring no elevated privileges and relying on a stored attack vector that can affect all users who view the affected pages.
OpenCVE Enrichment