Impact
The ARforms plugin for WordPress does not properly sanitize or escape values entered into the ‘password’ field. As a result, an attacker can submit arbitrary JavaScript that is stored in the plugin’s database. When any user opens the affected form page, the browser executes the stored code, allowing a client‑side compromise.
Affected Systems
All released versions of the ARforms WordPress plugin up to and including 7.2.1 are vulnerable. No publicly documented fixes are noted for newer releases.
Risk and Exploitability
The CVSS score of 7.2 classifies this as a high‑severity stored XSS flaw. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vuln is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated attacker submitting malicious payloads through the public ‘password’ field; the stored data is then served to all users who view the affected form.
OpenCVE Enrichment