The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HFluentforms Contact Form
APPFluentforms< 3.6.67
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
XSSLPE
Powiązane podatności
CVE-2024-2771CRITICAL9.8PL ✓ten sam produkt
Fluent Forms WordPress — privilege escalation przez brak weryfikacji uprawnień
CVE-2022-3463CRITICAL9.8PL ✓ten sam produkt
CSV injection w pluginie Fluent Forms Contact Form dla WordPress
CVE-2024-10646HIGH7.2ten sam produkt
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress...
CVE-2024-4157HIGH7.5ten sam produkt
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress...
CVE-2024-2782HIGH7.5ten sam produkt
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress...