Fluent Forms Quiz, Survey, and Drag & Drop WP Form Builder Plugin Vulnerable to Stored Cross-Site Scripting
CVE-2024-2772

6.4MEDIUM

Key Information:

Vendor
Techjewel
Status
Contact Form Plugin By Fluent Forms For Quiz, Survey, And Drag & Drop WP Form Builder
Vendor
CVE Published:
18 May 2024

Summary

The Contact Form Plugin developed by Fluent Forms for WordPress contains a vulnerability that allows for Stored Cross-Site Scripting (XSS). This flaw arises from inadequate input sanitization and output escaping in form settings present in all versions up to and including 5.1.13. Authenticated attackers who have access to the settings of Fluent Forms can exploit this vulnerability to inject arbitrary web scripts. These malicious scripts will execute whenever a user accesses a page that has been manipulated. Additionally, this vulnerability can be chained with another weakness, allowing even low-privileged users to inject harmful scripts into the site.

Affected Version(s)

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder * <= 5.1.13

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Tobias Weißhaar
.