Stored Cross-Site Scripting Vulnerability in Fluent Forms Contact Form Plugin for WordPress
CVE-2024-4709
5.4MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 18 May 2024
What is CVE-2024-4709?
The Contact Form Plugin by Fluent Forms is prone to a Stored Cross-Site Scripting vulnerability. This issue arises from a lack of sufficient input sanitization and output escaping in the 'subject' parameter. Authenticated attackers possessing contributor-level permissions or higher, with administrator-provided access, can exploit this vulnerability to inject arbitrary web scripts into pages. Consequently, these scripts execute whenever a user accesses the compromised page, posing significant risks to user data and overall site integrity.
Affected Version(s)
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder * <= 5.1.16