Impact
The CRM Perks Forms WordPress plugin contains an improper neutralization of user‑supplied input during page rendering, enabling reflected XSS. A malicious actor can inject and execute arbitrary client‑side scripts when a victim loads a crafted URL or form input, potentially leading to data theft, session hijacking, or malicious redirection.
Affected Systems
WordPress sites that have the CRM Perks Forms plugin installed with a version of 1.1.7 or earlier are impacted. Any newer release is presumed to incorporate the fix.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high severity, while the EPSS score of <1% indicates a low likelihood of current exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack does not require authentication; an attacker only needs to persuade a victim to visit a maliciously crafted URL or submit engineered input.
OpenCVE Enrichment