cleantalk
Vulnerabilities and Security Researches

Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder, CVE-2021-34620

CVE, Research URL

CVE-2021-34620

Published on
Jul 07, 2021
Research Description
The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions
Affected versions
Min -, max 3.6.67.
Status
vulnerable