Impact
The vulnerable Form Builder CP WordPress plugin fails to sanitize a form configuration value before embedding it in client‑side script, enabling authenticated users with Editor or higher access to inject malicious code into any page rendering the form. This Stored Cross‑Site Scripting can execute arbitrary JavaScript in the browser context of any visitor, leading to session hijacking, credential theft, or defacement, regardless of the site’s unfiltered_html restriction.
Affected Systems
This flaw affects the Form Builder CP plugin for WordPress versions prior to 1.2.47. It is relevant to any WordPress site that has installed this plugin and has users with Editor‑level or higher permissions.
Risk and Exploitability
The exploit requires an authenticated Editor or higher and is limited to pages displaying the vulnerable form. EPSS information is unavailable, and the vulnerability is not in CISA KEV. The impact is significant because the injected script runs with the victim’s browser context, while the attack surface is reduced by the editing privilege requirement.
OpenCVE Enrichment