The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HFluentforms Contact Form
APPFluentforms< 3.6.67
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XSSLPE
Related vulnerabilities
CVE-2024-2771CRITICAL9.8PL ✓same product
Fluent Forms WordPress — privilege escalation przez brak weryfikacji uprawnień
CVE-2022-3463CRITICAL9.8PL ✓same product
CSV injection w pluginie Fluent Forms Contact Form dla WordPress
CVE-2024-10646HIGH7.2same product
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress...
CVE-2024-4157HIGH7.5same product
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress...
CVE-2024-2782HIGH7.5same product
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress...