Impact
The Business Essentials for Contact Form 7 plugin on WordPress accepts unsanitized input in the 'gateway' form field and fails to escape it when rendering stored data. As a result, unauthenticated attackers can insert arbitrary JavaScript that will run in the browser of any user who views a page that includes the injected payload. The attacker can steal cookies, deface the site, or hijack user sessions, compromising the confidentiality and integrity of the affected WordPress site.
Affected Systems
All installations of the Business Essentials for Contact Form 7 plugin up to and including version 1.2.1 are affected, regardless of WordPress core version. The flaw exists only when the Payments module is enabled and a form is configured to accept PayPal and Stripe payment gateways. The vendor is Scott Paterson.
Risk and Exploitability
With a CVSS score of 7.2, the vulnerability is considered high severity. EPSS is not available, so the real‑world exploitation probability cannot be quantified, but the flaw can be triggered without authentication, making it readily exploitable in any site that meets the configuration prerequisites. The vulnerability is not listed in the CISA KEV catalog, yet the lack of authentication and stored nature mean that attackers can persistently compromise user interactions with the site. The likely attack vector is remote via HTTP form submission, where attackers submit crafted input to the gateway field and store the payload for later use.
OpenCVE Enrichment