Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw found in the Ultimate Addons for Contact Form 7 WordPress plugin versions 3.5.45 and earlier. It allows attackers to inject arbitrary JavaScript into webpages delivered by the plugin, potentially enabling malicious content to be displayed to site visitors. The weakness is categorized as CWE-79.
Affected Systems
WordPress sites that have the Themefic Ultimate Addons for Contact Form 7 plugin installed with a version up to and including 3.5.45 are at risk. Sites running versions newer than 3.5.45, or those that do not use the plugin, are not affected.
Risk and Exploitability
The flaw carries a CVSS score of 7.1, signifying high severity, and an EPSS score of <1%, indicating a low probability of exploitation. It is not listed in the CISA KEV catalog. Because authentication is not required, an attacker can trigger the XSS by submitting a crafted request to a vulnerable endpoint, potentially from any web browser or automated script. The overall risk is moderate, but the impact could include malicious content injection on affected pages.
OpenCVE Enrichment