Impact
The Contact Form by Supsystic plugin fails to sanitize and escape input that originates from the IP Address Header. An attacker can exploit this by forging a request that contains a malicious script in the X‑Forwarded‑For header. Because the vulnerable code writes the script into a stored contact form entry, the payload is persistently rendered on the site. Once a visitor loads the affected page, the embedded script executes in the context of the site, enabling actions such as cookie theft, session hijacking, or malicious redirects.
Affected Systems
All versions of the Contact Form by Supsystic plugin for WordPress up to and including 1.10.2 are affected. The plugin is distributed by supsysticcom and is typically installed on WordPress sites that host content assisted by contact forms.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity vulnerability that is likely to be of moderate to high exploitation risk. The EPSS score is not available, so the current likelihood of exploitation cannot be precisely quantified, but the lack of authentication controls on the updateNonce endpoint makes the attack straightforward to carry out. The vulnerability is not listed in the CISA KEV catalog, although interested operators should monitor for emerging exploits.
OpenCVE Enrichment