Impact
The vulnerability is caused by inadequate sanitization of the Range Slider’s 'data-label' and 'data-separator' inputs, allowing an authenticated contributor or higher to insert malicious JavaScript that is persisted in the plugin’s data structure. When any user visits a page containing the injected values, the embedded script executes within that user’s browser session, potentially leading to session hijacking, credential theft, or defacement. The flaw thus compromises the confidentiality and integrity of user sessions and the visual integrity of the site.
Affected Systems
The Ultra Addons for Contact Form 7 WordPress plugin, versions up to and including 3.5.43, is affected. Any WordPress installation that utilizes this plugin and assigns contributors or higher roles to users is exposed.
Risk and Exploitability
The CVSS score of 6.4 classifies this as a medium‑severity vulnerability; the EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Attack vectors are limited to authenticated accounts with contributor roles or greater, meaning that the attacker must first gain at least contributor-level access. Once that precondition is met, the stored XSS payload can be delivered to all users who view a page containing the vulnerable slider, resulting in persistent client‑side exploitation.
OpenCVE Enrichment