Impact
Unauthenticated Cross‑Site Scripting (XSS) exists in the WordPress "Contact Form to Any API" plugin versions 3.0.3 and earlier. The flaw allows an attacker to inject arbitrary JavaScript into pages served by the site, potentially leading to session hijacking, defacement, or phishing attacks against unsuspecting visitors.
Affected Systems
The vulnerability affects users of the IT Path Solutions "Contact Form to Any API" plugin for WordPress running any release version up to and including 3.0.3. The affected component is the form processing code that fails to properly sanitize input received from form submissions.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity, while the EPSS score of less than 1% indicates a low probability of discovery and exploitation in the wild. Because the XSS is unauthenticated, an attacker need only craft and submit a malicious payload through the public form to trigger it, making the attack vector easily reachable from the client side. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely leveraged in documented attacks.
OpenCVE Enrichment