Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder, CVE-2021-34620
- CVE, Research URL
- Home page URL
- Application
-
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
- Published on
- Jul 07, 2021
- Research Description
- The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Privilege Escalation due to a missing nonce check in the access control function for administrative AJAX actions
- Affected versions
-
Min -, max 3.6.67.
- Status
-
vulnerable