Stored Cross-Site Scripting in Contact Form Plugin by Fluent Forms for WordPress
CVE-2024-0618
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 January 2024
What is CVE-2024-0618?
The Fastest Contact Form Builder Plugin for WordPress by Fluent Forms is exposed to Stored Cross-Site Scripting vulnerabilities through improperly sanitized form titles. This vulnerability affects all versions up to and including 5.1.5, allowing authenticated attackers with administrator access to inject malicious scripts. The exploited scripts can execute when users access compromised pages, primarily impacting multi-site setups or instances where unfiltered HTML is disabled.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Contact Form Plugin β Fastest Contact Form Builder Plugin for WordPress by Fluent Forms * <= 5.1.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved