Vulnerabilities and security researches forfluentform fluentform
Direction: ascendingContact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2021-34620
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Jul 07, 2021
- Research Description
- The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2022-3463
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Nov 07, 2022
- Research Description
- The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2023-6957
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Mar 13, 2024
- Research Description
- The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.9 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploitation level depends on who is granted the right to create forms by an administrator. This level can be as low as contributor, but by default is admin.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2023-0546
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Apr 10, 2023
- Research Description
- The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML field type, allowing a logged in user with roles as low as contributor to inject arbitrary javascript into a form which will trigger for any visitor to the form or admins previewing or editing the form.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2023-24410
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Oct 31, 2023
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPManageNinja LLC Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms fluentform allows SQL Injection.This issue affects Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms: from n/a through 4.3.25.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-4709
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- May 18, 2024
- Research Description
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subject’ parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, and access granted by an administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-4157
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- May 22, 2024
- Research Description
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. Successful exploitation requires the attacker to have "View Form" and "Manage Form" permissions, which must be explicitly set by an administrator. However, this requirement can be bypassed when this vulnerability is chained with CVE-2024-2771.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-0618
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Jan 27, 2024
- Research Description
- The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via imported form titles in all versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-2782
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- May 18, 2024
- Research Description
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to modify all of the plugin's settings.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-2771
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- May 18, 2024
- Research Description
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin's settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-2772
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- May 18, 2024
- Research Description
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the Fluent Forms settings, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This can be chained with CVE-2024-2771 for a low-privileged user to inject malicious web scripts.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2023-41952
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Dec 13, 2024
- Research Description
- Missing Authorization vulnerability in Contact Form - WPManageNinja LLC FluentForm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through 5.0.8.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-6521
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Jul 27, 2024
- Research Description
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-6518
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Jul 27, 2024
- Research Description
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-6520
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Jul 27, 2024
- Research Description
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-6703
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Jul 27, 2024
- Research Description
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘description’ and 'btn_txt' parameters in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for attackers with the Form Manager permissions and Subscriber+ user role, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-5053
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Sep 01, 2024
- Research Description
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp API key update due to an insufficient capability check on the verifyRequest function in all versions up to, and including, 5.1.18. This makes it possible for Form Managers with a Subscriber-level access and above to modify the Mailchimp API key used for integration. At the same time, missing Mailchimp API key validation allows the redirect of the integration requests to the attacker-controlled server.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-9528
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Oct 05, 2024
- Research Description
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form label fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to edit forms (administrator by default), to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # PSC-2024-64530
- PSC, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Apr 15, 2025
- Research Description
- Fluent Forms has passed a thorough security assessment and received the prestigious Plugin Security Certification (PSC) from CleanTalk, which guarantees users a secure environment for managing forms. Fluent Forms is a comprehensive and secure contact form builder designed for WordPress. With an intuitive drag-and-drop interface, Fluent Forms provides a wide range of features that are suitable for both beginners and advanced users. Recognized for its performance, Fluent Forms loads quickly without overloading your site and offers a wide range of powerful form functionality. The security features of the plugin ensure the protection of user data, and the advanced customization options make it a universal choice for any WordPress website. And now, thanks to the security certification of the plugin (PSC-2024-64530) from CleanTalk, you can use Fluent Forms with a guarantee of increased security. This certification confirms that Fluent Forms has passed a thorough security check, which makes it a reliable means of managing the contact form builder without introducing vulnerabilities to your WordPress site.
- Affected versions
-
Min -, max -.
- Status
-
SAFE & CERTIFIED
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-9651
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Dec 09, 2024
- Research Description
- The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-10646
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Dec 14, 2024
- Research Description
- The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2024-13666
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Mar 22, 2025
- Research Description
- The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 5.2.12 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers spoof their IP address and submit forms that may have IP-based restrictions.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder # CVE-2025-3615
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Date
- Apr 17, 2025
- Research Description
- The Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form-submission.js script in all versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable