Impact
The vulnerability is an unauthenticated cross‑site scripting flaw in the WordPress Happyforms plugin up to version 1.26.15. An attacker can inject arbitrary JavaScript into a form or page rendered by the plugin, potentially allowing script execution in visitors’ browsers, cookie theft, session hijacking, or page defacement. The impact is limited to client‑side code execution but can be leveraged to compromise site integrity or to launch further phishing attacks. The weakness is identified as CWE‑79, reflecting improper sanitization of user input.
Affected Systems
The affected system is the WordPress Happyforms plugin by Happyforms. All installations of Happyforms version 1.26.15 or earlier are vulnerable. The plugin is commonly deployed on WordPress sites that use the Happyforms contact and feedback form functionality.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, and the entry is not listed in the CISA KEV catalog, but the flaw is unauthenticated and can be exploited simply by visiting a crafted URL or submitting a malicious form. If a site is publicly accessible, the risk is moderate to high, especially for users with active sessions, and attackers can repeatedly attempt to inject malicious payloads. The lack of an authentication requirement makes the attack simpler, although the impact remains client‑side and requires user interaction.
OpenCVE Enrichment