Impact
The vulnerability is a Cross Site Scripting flaw present in WPZOOM Forms – Contact Form Plugin for Gutenberg up to version 2.0.4. It allows an attacker to inject malicious scripts that are executed in the context of a user’s browser when the compromised content is displayed, potentially enabling session hijacking, defacement, or other malicious actions on the victim’s behalf. The weakness is classified as CWE‑79.
Affected Systems
WPZOOM Forms – Contact Form Plugin for Gutenberg, versions 2.0.4 and earlier, used on WordPress sites.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium to high risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through user interaction with the plugin’s form or settings page, and the flaw may be exploitable by an unauthenticated or low‑privileged user who can submit crafted form data. Given the lack of a public exploit and the absence of a KEV listing, exploitation is considered possible but not confirmed.
OpenCVE Enrichment