Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation, also known as Reflected Cross‑Site Scripting. When input is submitted through the Contact Form Entries plugin, the data is reflected back to the page without adequate sanitization, which allows an attacker to deliver and execute arbitrary JavaScript in the victim’s browser. This flaw enables the execution of client‑side code originating from user input.
Affected Systems
The affected product is the WordPress plugin Contact Form Entries by CRM Perks. All releases from the initial revision through version 1.5.2 are impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. The EPSS score of less than 1 % indicates a low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could send or embed a malicious payload that is reflected by the plugin and then executed in the victim’s browser when the page is viewed.
OpenCVE Enrichment