Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms crm-perks-forms allows Reflected XSS.This issue affects CRM Perks Forms: from n/a through <= 1.1.7.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CRM Perks Forms WordPress plugin contains an improper neutralization of user‑supplied input during page rendering, enabling reflected XSS. A malicious actor can inject and execute arbitrary client‑side scripts when a victim loads a crafted URL or form input, potentially leading to data theft, session hijacking, or malicious redirection.

Affected Systems

WordPress sites that have the CRM Perks Forms plugin installed with a version of 1.1.7 or earlier are impacted. Any newer release is presumed to incorporate the fix.

Risk and Exploitability

The CVSS score of 7.1 classifies the vulnerability as high severity, while the EPSS score of <1% indicates a low likelihood of current exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack does not require authentication; an attacker only needs to persuade a victim to visit a maliciously crafted URL or submit engineered input.

Generated by OpenCVE AI on July 31, 2026 at 11:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the CRM Perks Forms plugin to a version newer than 1.1.7, which includes the XSS fix.
  • If an upgrade is not possible immediately, temporarily disable or delete the plugin to eliminate the vulnerability.
  • Implement server‑side sanitization or output encoding for all user input handled by the plugin, for example by using WordPress functions such as esc_html to encode output.

Generated by OpenCVE AI on July 31, 2026 at 11:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Crmperks
Crmperks crm Perks Forms
Wordpress
Wordpress wordpress
Vendors & Products Crmperks
Crmperks crm Perks Forms
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms crm-perks-forms allows Reflected XSS.This issue affects CRM Perks Forms: from n/a through <= 1.1.7.
Title WordPress CRM Perks Forms plugin <= 1.1.7 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Crmperks Crm Perks Forms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:51.774Z

Reserved: 2026-06-24T12:46:38.624Z

Link: CVE-2026-57421

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:16.528Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')