Impact
A contributor cross‑site scripting flaw exists in the Ultimate Addons for Contact Form 7 plugin versions up to 3.5.50. The vulnerability allows malicious input to be stored or displayed as arbitrary HTML or JavaScript, potentially enabling session hijacking, defacement, or the injection of tracking or phishing code in end‑user browsers. The weakness is based on CWE‑79 and does not provide direct remote code execution, but it can undermine confidentiality, integrity, and availability of the site for visitors.
Affected Systems
The affected product is the Themefic Ultimate Addons for Contact Form 7 WordPress plugin. Any installation running a version equal to or older than 3.5.50 is vulnerable. The vulnerability affects all sites that use the plugin to render contact forms or related extensions.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity rating. The EPSS score is not available, and the issue is currently not listed in CISA’s KEV catalog. The likely attack vector is through the plugin’s user‑facing input fields or configuration pages, where an attacker could inject malicious code. Exploitation would require the attacker to submit crafted data or otherwise interact with the vulnerable plugin interfaces, after which the malicious script would execute in the browsers of site visitors.
OpenCVE Enrichment