Impact
The Form Vibes plugin for WordPress does not from Contact Form 7 form fields before storing them in the database. Attackers can embed arbitrary JavaScript that is then executed automatically whenever a page displaying that stored entry is accessed.
Affected Systems
All WordPress sites that have the wpvibes Form V7 & Elementor Form Entries to Database plugin installed and enabled in version 1.5.2 or earlier are affected. Any public Contact Form 7 form that submits data through the plugin’s storage mechanism can be used to inject malicious code, and no user authentication is required to perform the attack.
Risk and Exploitability
With a CVSS score of 7.2 the vulnerability is high severity, yet the EPSS score of less than 1 % indicates a low likelihood of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach exploitable input points via the public form submission endpoint, making the attack vector web‑based and unauthenticated. If exploited, malicious code persists and runs for every user who views the impacted entry.
OpenCVE Enrichment