Impact
The vulnerability is a stored cross‑site scripting flaw in the Infility Global WordPress plugin. It allows an unauthenticated attacker to submit malicious script payloads to the /cf7_record log endpoint, which are persisted and rendered unescaped when any authenticated user, including low‑privileged subscribers, accesses the /cf7_records viewer. The injected scripts can hijack user sessions, steal data, or perform arbitrary actions on behalf of the victim.
Affected Systems
The affected system is the Infility Global plugin for WordPress. All released versions up to and including 2.15.21 contain the flaw. WordPress sites that have installed any of these versions are vulnerable, regardless of the site’s user role distribution.
Risk and Exploitability
The CVSS score of 7.2 classifies the issue as a high‑severity cross‑site scripting vulnerability. The EPSS metric is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs to post a malicious script to the log endpoint, which is accessible without authentication. Once injected, the script executes in the context of any logged‑in user who views the records page, allowing the attacker to run arbitrary code within the victim’s browser session.
OpenCVE Enrichment