WP Fluent Forms < 3.6.67 - Stored Cross-Site Scripting
2021-06-16 00:00
RamStrategic Overview
StatusPatched in 3.6.67
Affected PluginFluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
Affected Version
< 3.6.67CVSS8.8High
CVE
CVE-2021-34620Vulnerability Overview
The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions
Technical Analysis
REMEDIATION: Update to version 3.6.67, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C