What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POWR.Io Contact Form – Custom Builder, Payment Form, and More allows Stored XSS.This issue affects Contact Form – Custom Builder, Payment Form, and More: from n/a through 2.1.0.
Explanation of Vulnerability in Simple Terms
02Summary
The Contact Form plugin for POWR.io contains a stored cross-site scripting (XSS) vulnerability in versions up to 2.1.0. An authenticated user with low privileges can inject malicious scripts into form fields. When other users view the affected form or its data, the injected code executes in their browser, potentially compromising their session or stealing sensitive information.
What an attacker can do
03Attacker Capabilities
Inject malicious JavaScript that executes when other users view the form or submitted data.
Potential impact on your site
04Site Impact
User sessions and data could be compromised if attackers inject scripts into your contact forms.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the site and the victim must view the affected form or data.
Key dates
06Disclosure timeline
November 30, 2023
CVE published
April 28, 2026
Record updated