Impact
The vulnerability is a reflected XSS flaw that allows unauthenticated users to inject arbitrary scripts into the ARForms plugin’s output. When a crafted URL or payload is triggered, the script can run in the context of the visitor’s browser, potentially stealing session cookies, defacing content, or performing malicious actions on behalf of the user. Because the flaw is unauthenticated, any site visitor can exploit it without needing to log in.
Affected Systems
The issue affects the WordPress ARForms plugin developed by Repute InfoSystems, specifically all versions up to and including 7.1.2. Sites that have deployed any of these vulnerable versions are at risk until the plugin is updated.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation yet, but the potential for abuse remains high given the unauthenticated nature of the flaw. The likely attack vector involves sending a specially crafted URL to users or embedding malicious form parameters that are returned unsanitized in the plugin output.
OpenCVE Enrichment