Impact
The vulnerability arises from insufficient input sanitization and output escaping of the cntctfrm_contact_dropdown parameter in the Contact Form to DB plugin. This leads to a Stored Cross‑Site Scripting (CWE‑79) flaw, enabling unauthenticated attackers to inject malicious scripts. When an administrator later visits the plugin’s message manager page at /wp-admin/admin.php?page=cntctfrmtdb_manager, the injected payload executes in the administrator’s browser context, potentially giving the attacker control of the admin session.
Affected Systems
All WordPress sites running the Contact Form to DB plugin version 1.7.5 or earlier are affected. The vulnerability is specific to the plugin developed by BestWebSoft and impacts sites that have the plugin installed and its form functionality exposed.
Risk and Exploitability
The CVSS base score is 7.2, indicating a high impact severity; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, as an attacker can submit a crafted form from any location without authentication. Because the flaw is stored, the attacker only needs to wait for an administrator to open the message manager page, making it a straightforward exploitation scenario for attackers with internet access to the affected site.
OpenCVE Enrichment