Impact
The vulnerability allows an attacker to inject arbitrary JavaScript into a page that a visitor might open in a browser. The flaw is due to insufficient sanitization of a query string key referenced by the {query_var} smart tag, which is rendered inside an iframe srcdoc attribute. An attacker can exploit this when a form description containing the smart tag is displayed publicly and the user follows a crafted link that supplies a malicious value for the key. The resulting script runs in the context of the site, enabling data theft, cookie theft, or redirection.
Affected Systems
WordPress sites running the WPForms – AI Form Builder for WordPress plugin version 2.0.2.1 or earlier. The plugin is used for creating contact, payment, survey, quiz and other forms. Any site administrator who has saved a form whose description embeds a {query_var} smart tag inside an iframe srcdoc attribute and has enabled the display of the description on a public page is susceptible.
Risk and Exploitability
The CVSS score of 4.7 categorizes the flaw as moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. However, the requirement that the site already displays a vulnerable form means attackers can target sites that expose such forms, using social engineering to lure users to click a malicious link. The impact is limited to the victim’s browser and does not compromise the server directly.
OpenCVE Enrichment