Impact
The vulnerability is an unauthenticated XSS flaw that permits attackers to inject arbitrary JavaScript into web pages served by a WordPress site that has the Download Monitor – WPForms Lock plugin v1.0.4 or earlier. Based on the description, it is inferred that the attacker can interact with the plugin’s publicly exposed front‑end interface without authentication. Successful injection can lead to theft of user cookies, session hijacking, phishing, and defacement of the site’s content, thereby affecting confidentiality, integrity, and availability of the client‑side experience.
Affected Systems
Affected systems are WordPress sites that have the Download Monitor – WPForms Lock plugin at version 1.0.4 or lower. The plugin, supplied by Download Monitor, restricts file downloads to users who complete a WPForms form. Any site that retains this outdated plugin remains vulnerable.
Risk and Exploitability
The CVSS score of 7.1 signals moderate‑to‑high severity, and the EPSS score of less than 1% indicates a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, yet advisories already recommend patching. Based on the lack of authentication requirement and inferred that any publicly exposed site with the plugin can be targeted, an attacker could embed malicious payloads in a link or form on the site; mitigating steps include upgrading to version 1.0.5 or later and implementing a content security policy. The risk is that attackers can leverage the flaw through any publicly reachable page where the plugin outputs unsanitized user data. The attack vector is inferred to be through the plugin’s front‑end or any form‑rendering page, and no authorization is required, thus the potential impact spans confidentiality, integrity, and availability of the client experience. Because the EPSS is low, immediate exposure risk is modest, but the severity remains high enough to warrant prompt patching.
OpenCVE Enrichment