Stored Cross-Site Scripting Vulnerability in Fluent Forms Contact Form Plugin for WordPress
CVE-2024-4709

7.2HIGH

Summary

The Contact Form Plugin by Fluent Forms is prone to a Stored Cross-Site Scripting vulnerability. This issue arises from a lack of sufficient input sanitization and output escaping in the 'subject' parameter. Authenticated attackers possessing contributor-level permissions or higher, with administrator-provided access, can exploit this vulnerability to inject arbitrary web scripts into pages. Consequently, these scripts execute whenever a user accesses the compromised page, posing significant risks to user data and overall site integrity.

Affected Version(s)

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder * <= 5.1.16

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tobias Weißhaar
.