Stored Cross-Site Scripting Vulnerability in Fluent Forms Contact Form Plugin for WordPress
CVE-2024-4709
7.2HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 18 May 2024
Summary
The Contact Form Plugin by Fluent Forms is prone to a Stored Cross-Site Scripting vulnerability. This issue arises from a lack of sufficient input sanitization and output escaping in the 'subject' parameter. Authenticated attackers possessing contributor-level permissions or higher, with administrator-provided access, can exploit this vulnerability to inject arbitrary web scripts into pages. Consequently, these scripts execute whenever a user accesses the compromised page, posing significant risks to user data and overall site integrity.
Affected Version(s)
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder * <= 5.1.16
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tobias Weißhaar