Impact
The Magic Tooltips For Contact Form 7 plugin is vulnerable to stored cross‑site scripting because the esc_html filter callback decodes HTML‑entity‑encoded payloads, allowing an attacker to submit a comment author name containing an encoded script. The stored author name is rendered as executable markup when an administrator views comments, enabling arbitrary code execution in the context of wp‑admin. This flaw is a classic client‑side injection (CWE‑79).
Affected Systems
Magic Tooltips For Contact Form 7 plugin for WordPress versions up to and including 1.0.34.
Risk and Exploitability
The vulnerability can be triggered by any unauthenticated user who can add a comment, since the comment author field is not sanitized. The exploit requires only writing a comment with an entity‑encoded script; no special privileges or user interaction are needed beyond an administrator viewing the stored comment. The CVSS base score of 7.2 indicates a high severity. Because the exploit is straightforward and no EPSS score is available, the likelihood of exploitation is uncertain, but the known use of the author field suggests that attackers can easily craft payloads. The vulnerability is not listed in the CISA KEV catalog, but it remains a serious risk for sites using the plugin.
OpenCVE Enrichment