Impact
A contributor cross‑site scripting flaw exists in WordPress CF7 Views – Complete Entry Management for Contact Form 7 versions 3.2.5 and earlier, allowing malicious users with contributor privileges to inject arbitrary JavaScript into the plugin’s output. The vulnerability is a classic broken input validation issue (CWE‑79) that can compromise the integrity of web pages, steal session cookies, or deface site content.
Affected Systems
The affected product is the WordPress CF7 Views – Complete Entry Management for Contact Form 7 plugin, specifically all releases up to and including 3.2.5. Any WordPress installation that has this plugin installed and not upgraded to 3.2.6 or newer is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact level. No EPSS or KEV listing is available, suggesting limited publicly known exploitation. Because the flaw requires contributor or higher privileges, the attack vector is likely authenticated rather than remote. An attacker who gains contributor access can embed harmful scripts that will run in the context of users who view the affected pages, potentially leading to data theft or defacement. The overall risk is moderate, focused on accounts that can submit or edit form entries.
OpenCVE Enrichment