Impact
A stored cross‑site scripting flaw arises from the FormyChat plugin’s failure to neutralize user input before rendering it within a web page. A malicious user can submit script code through the plugin’s form container, and that code will be persisted and subsequently executed in the browsers of any visitor who loads can enable data theft, page defacement, or phishing attacks.
Affected Systems
WordPress sites that have installed the WPPOOL FormyChat plugin in any version up to and including 2.15.3. Any installation of the plugin in these releases is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity vulnerability. An EPSS score of less than 1% suggests that exploit attempts are rare, and the vulnerability is not listed in the CISA KEV catalog, so no widespread incidents are currently reported. Exploitation requires the attacker to deposit a malicious payload via the plugin’s input interface; once stored, the payload will be delivered to all users who view the affected page. Because the flaw is client‑side, an attacker can carry out the attack remotely through the form fields, impacting all site visitors.
OpenCVE Enrichment