Impact
This vulnerability is an unauthenticated XSS flaw in the CformsII WordPress plugin that allows an attacker to inject arbitrary scripts into form inputs. The injected code can run in the browsers of anyone who views the affected page, enabling defacement, theft of session cookies, or redirection to malicious sites. The weakness is a classic unsanitized input that violates confidentiality, integrity, and availability (via user experience degradation).
Affected Systems
The flaw affects the WordPress plugin CformsII (vendor bgermann), in all releases up to and including version 15.1.3. Versions 15.1.4 and later contain the mitigation.
Risk and Exploitability
The CVSS score of 7.1 classifies this as high severity. The EPSS score is indicated as less than 1%, suggesting a very low but non–zero likelihood of exploitation at this time. It has not been listed in the CISA KEV catalog. The most probable attack vector is an unauthenticated attacker delivering malicious data via any publicly accessible form field, after which the script executes in a visitor’s browser.
OpenCVE Enrichment