Impact
The SurveyJS Drag & Drop Form Builder plugin for WordPress is vulnerable to stored cross‑site scripting. Unsanitized survey submissions allow an attacker to inject HTML‑encoded payloads that are saved and later rendered as executable code when an administrator views survey results. This flaw, identified as CWE‑79, can lead to arbitrary script execution within the administrative interface, potentially compromising confidentiality, integrity, or availability of the site.
Affected Systems
The vulnerability affects the devsoftbaltic SurveyJS Drag & Drop Form Builder plugin for WordPress in all publicly released versions up to and including 2.5.3. Sites running any of these releases are at risk if the plugin remains active.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate‑to‑high severity. An EPSS score is not available and the flaw is not listed in the CISA KEV catalog, so the likelihood of exploitation is uncertain. The attack vector is inferred to be unauthenticated: the public survey page exposes the required nonce, enabling any visitor to submit malicious payloads that are stored and later rendered in the admin context. No additional prerequisites or privileges are required beyond the ability to submit a survey response.
OpenCVE Enrichment