Fluent Forms Quiz, Survey, and Drag & Drop WP Form Builder Plugin Vulnerable to Stored Cross-Site Scripting
CVE-2024-2772
Key Information:
- Vendor
- Techjewel
- Status
- Contact Form Plugin By Fluent Forms For Quiz, Survey, And Drag & Drop WP Form Builder
- Vendor
- CVE Published:
- 18 May 2024
Summary
The Contact Form Plugin developed by Fluent Forms for WordPress contains a vulnerability that allows for Stored Cross-Site Scripting (XSS). This flaw arises from inadequate input sanitization and output escaping in form settings present in all versions up to and including 5.1.13. Authenticated attackers who have access to the settings of Fluent Forms can exploit this vulnerability to inject arbitrary web scripts. These malicious scripts will execute whenever a user accesses a page that has been manipulated. Additionally, this vulnerability can be chained with another weakness, allowing even low-privileged users to inject harmful scripts into the site.
Affected Version(s)
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder * <= 5.1.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved