Impact
This vulnerability allows an unauthenticated attacker to inject malicious script through the Calculation For Contact Form 7 plugin as it does not properly sanitize or validate user input passed to the plugin. The injected script would execute in the context of any visitor who loads a page containing the vulnerable form, potentially enabling data theft, session hijacking, or defacement. The weakness is classified as a classic XSS flaw (CWE‑79).
Affected Systems
The affected product is the Calculation For Contact Form 7 plugin released by silverplugins217. All releases up to and including version 1.0 are vulnerable. The plugin versions 1.1 and later contain the fix.
Risk and Exploitability
The CVSS score of 7.1 assigns this issue a high severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no documented exploit at this time. The attack vector is likely through the public form interface, with no authentication required. An attacker could simply submit crafted input, cause the script to be stored or rendered, and exploit any site visitor who loads the affected page.
OpenCVE Enrichment